Plat-Arch-203 Sample Questions & Answers
Bringing outside identities into Salesforce carries the most weight, next to issuing tokens through OAuth, requiring a second login step, assigning roles during single sign-on, Identity Connect and Customer 360 Identity, and extending logins to partner communities.
Launch the full Plat-Arch-203 simulator →Showing 6 of 12 free samples.
- Question 1IntermediateSelect 2
Access Management Best Practices · Multi-Factor Authentication Methods and Sessions
Which TWO statements accurately describe the behavior of the 'High Assurance' session security level in Salesforce? (Select TWO)
Show answer & explanation
Correct answers: B, E
By default, Multi-Factor Authentication is defined as High Assurance. While you can move other methods there, MFA is the primary mechanism.
This describes session elevation. If a policy requires High Assurance and the current session is Standard, Salesforce prompts for a second factor.
- Question 2Advanced
Accepting Third-Party Identity in Salesforce · Third-Party Authentication Mechanisms
A developer is building a custom mobile application for a partner community. The app needs to authenticate users via Salesforce using OpenID Connect. The partner users should be able to log in using their LinkedIn credentials, which are already configured as an Auth Provider in Salesforce. Which specific parameter must be included in the authorization request to the Salesforce OAuth 2.0 endpoint to direct the user specifically to the LinkedIn login page, bypassing the standard Salesforce username/password screen?
Show answer & explanation
Correct answer: E
To initiate a specific Auth Provider flow directly (bypassing the Salesforce login selection screen), the client should direct the user to the specific SSO initialization URL for that Auth Provider:
https://[domain].my.site.com/services/auth/sso/[OrgID]/[AuthProviderName]. - Question 3Intermediate
Access Management Best Practices · Connected App Configuration Settings
True or False: When configuring a Connected App for an external web application to use Salesforce as an Identity Provider, enabling 'High Assurance' in the Connected App's Session Policies will automatically force the user to complete Multi-Factor Authentication every time they access the external application, regardless of their current Salesforce session state.
Show answer & explanation
Correct answer: B
False. If the user already has a valid High Assurance session in Salesforce (e.g., they logged in with MFA earlier), Salesforce will not force them to re-authenticate for the Connected App unless the session has expired or the policy is explicitly set to 'Raise the session level to High Assurance' and the current session is only Standard.
- Question 4Intermediate
Community (Partner and Customer) · Customizing Experience Cloud User Experience
A healthcare provider is setting up an Experience Cloud site for patients. They require patients to register using a custom form that captures Medical Record Number (MRN) and Date of Birth. This information must be validated against an external legacy database before the Salesforce User record is created. Which mechanism should the Identity Architect use to implement this validation logic?
Show answer & explanation
Correct answer: D
Standard self-registration cannot perform real-time external callouts for validation before creation. A custom Lightning Web Component (Configurable Self-Reg) invoking an Apex controller allows the architect to call the external API, validate the MRN/DOB, and then programmatically create the user only if validation succeeds.
- Question 5Intermediate
Accepting Third-Party Identity in Salesforce · Provisioning Users for SSO with Access Rights
A company is implementing Single Sign-On (SSO) where Salesforce acts as the Service Provider and Okta as the Identity Provider. They want to ensure that if a user's department changes in Okta, the corresponding Profile in Salesforce is automatically updated upon their next login. The Architect decides to use a SAML JIT Handler. Which interface method must be implemented to handle returning users?
Show answer & explanation
Correct answer: C
The
Auth.SamlJitHandlerinterface requires the implementation ofcreateUserfor new users andupdateUserfor existing users. TheupdateUsermethod is called when the Federation ID matches an existing user, allowing logic to update fields like Profile or Role based on the latest SAML assertions. - Question 6Advanced
Community (Partner and Customer) · External IdPs and User/Contact Models in Communities
Case Study:
Company Overview
TechGlobal is a software provider with a Salesforce org for employees and an Experience Cloud site for partners. They use Azure AD as their corporate IdP.Current Situation
Partners currently log in with username/password stored in Salesforce. TechGlobal wants to migrate partners to use their own corporate credentials (various IdPs including Okta, Ping, and Azure AD) via OpenID Connect.Requirement
TechGlobal does not want to configure a separate Auth Provider for every partner company. They want a centralized way to route authentication requests to the correct partner IdP based on the user's email domain.Question
Which architecture is the most scalable solution to meet this requirement?Show answer & explanation
Correct answer: D
Since Salesforce does not natively support dynamic routing to hundreds of different IdPs based on email domain without configuring each one individually (which hits limits and maintenance issues), the best architectural pattern is to use an upstream Identity Broker. Salesforce trusts the Broker, and the Broker handles the complexity of routing users to their specific corporate IdP.
Ready for the real thing?
The full Plat-Arch-203 simulator has every exam-style question, timed mode, and instant scoring.