Salesforce Plat-Arch-203 考試概覽:
| 認證廠商: | Salesforce |
| 考試名稱: | Salesforce Certified Platform Identity and Access Management Architect Exam |
| 考試代碼: | Plat-Arch-203 |
| 及格分數: | 約 65%(Salesforce 可能會進行調整) |
| 考試費用: | USD 200 |
| 實際考試題數: | 60-65 |
| 支援語言: | English |
| 證照有效期限: | 需要維護;通常需要透過 Salesforce 發行版本考試進行定期認證維護(若持續維護則無固定有效期限) |
| 考試形式: | 單選題, 多選題 |
| 相關認證: | Salesforce Certified Identity and Access Management Designer Salesforce Certified Application Architect Salesforce Certified System Architect |
| 考試時間: | 120 minutes |
| 推薦課程: | 身分與存取管理架構師 Trailmix Trailhead 身分基礎模組 |
| 考試報名: | Salesforce 認證註冊 Salesforce 憑證考試指南 |
| 範例考題: | Salesforce Plat-Arch-203 範例考題 |
| 考試方式: | 線上監考或授權測試中心 |
| 必備條件: | 建議:Salesforce 認證身分與存取管理設計師,以及架構師級別的 Salesforce 經驗 |
| 官方大綱網址: | https://trailhead.salesforce.com/credentials/architect |
Salesforce Plat-Arch-203 考試大綱主題:
| 章節 | 目標 |
|---|---|
| API 與整合安全性 | - Token 管理與重新整理機制 - 安全整合模式 - OAuth 範圍與 API 驗證流程 |
| 身分與存取管理基礎 | - 身分生命週期管理概念 - 驗證與授權原則 - 企業身分架構基礎 |
| 驗證與單一登入 (SSO) | - SSO 疑難排解與設定 - Salesforce 中的 SAML 2.0 實作 - OpenID Connect 與 OAuth 2.0 流程 |
| 存取管理與安全性控制 | - 多因素驗證 (MFA) 強制執行 - 工作階段管理與安全性策略 - 設定檔、權限集與角色階層 |
| Salesforce 身分服務 | - Identity Connect 與外部身分提供者 - My Domain 與身分設定 - Connected Apps 與 OAuth 策略 |
| Experience Cloud 與外部身分 | - 社群登入與身分提供者 - 外部使用者驗證與授權 - B2B 與 B2C 身分考量因素 |
最新的 Identity and Access Management Designer Plat-Arch-203 免費考試真題:
1. Universal Containers (UC) wants to build a custom mobile app for their field reps to create orders in salesforce. After the first time the users log in, they must be able to access salesforce upon opening the mobile app without being prompted to log in again. What Oauth flows should be considered to support this requirement?
A) SAML Assertion flow with a Bearer Token.
B) User Agent flow with a Refresh Token.
C) Web Server flow with a Refresh Token.
D) Mobile Agent flow with a Bearer Token.
2. Northern Trail Outfitters (NTO) believes a specific user account may have been compromised. NTO inactivated the user account and needs U perform a forensic analysis and identify signals that could Indicate a breach has occurred.
What should NTO's first step be in gathering signals that could indicate account compromise?
A) Download the Setup Audit Trail and review all recent activities performed by the user.
B) Download the Login History and evaluate the details of logins performed by the user.
C) Download the Identity Provider Event Log and evaluate the details of activities performed by the user.
D) Review the User record and evaluate the login and transaction history.
3. A pharmaceutical company has an on-premise application (see illustration) that it wants to integrate with Salesforce.
The IT director wants to ensure that requests must include a certificate with a trusted certificate chain to access the company's on-premise application endpoint.
What should an Identity architect do to meet this requirement?
A) Generate a certificate authority-signed certificate in Salesforce and uploading it to the on-premise application Truststore.
B) Upload a third-party certificate from Salesforce into the on-premise server.
C) Use open SSL to generate a Self-signed Certificate and upload it to the on-premise app.
D) Configure the company firewall to allow traffic from Salesforce IP ranges.
4. Northern Trail Outfitters would like to automatically create new employee users in Salesforce with an appropriate profile that maps to its Active Directory Department.
How should an identity architect implement this requirement?
A) Make a callout during the login flow to query department from Active Directory to assign the appropriate profile.
B) Use the createUser method in the Just-in-Time (JIT) provisioning registration handler to assign the appropriate profile.
C) Use a login flow to collect Security Assertion Markup Language attributes and assign the appropriate profile during Just-In-Time
D) Use the updateUser method in the Just-in-Time (JIT) provisioning registration handler to assign the appropriate profile.
5. Universal Containers wants to allow its customers to log in to its Experience Cloud via a third party authentication provider that supports only the OAuth protocol.
What should an identity architect do to fulfill this requirement?
A) Use certificate-based authentication.
B) Contact Salesforce Support and enable delegate single sign-on.
C) Configure OpenID Connect authentication provider.
D) Create a custom external authentication provider.
問題與答案:
| 問題 #1 答案: B | 問題 #2 答案: B | 問題 #3 答案: D | 問題 #4 答案: D | 問題 #5 答案: D |

下載最新試用版
973位客戶反饋
我們對我們的產品非常有信心,所以我們不提供会给客户带去麻煩的產品。








61.231.124.* -
真的好意外,我第一次就通過了 Plat-Arch-203 考試。很感謝我的朋友推薦給我的 VCESoft 網站的考試資料,讓我以非常好的成績通過了Plat-Arch-203考試。