- Home
- Salesforce
- Identity-and-Access-Management-Architect Exam Questions
Salesforce Identity-and-Access-Management-Architect Practice Exam Questions & Answers
6 Free Questions
· Last reviewed: September 30, 2026
· Prepared & Reviewed by the ValidExamDumps Editorial Team
Exam Facts
Salesforce Identity-and-Access-Management-Architect Exam Details
Key details for this exam, checked against the published exam outline
248
Practice Questions (Our Bank)
120 minutes
Exam Duration
67% (approximately 40 out of 60 questions)
Passing Score
USD 400
Official Exam Fee
- Exam Code
- Identity-and-Access-Management-Architect
- Full Name
- Salesforce Certified Platform Identity and Access Management Architect
- Issuing Body
- Salesforce
- Question Format (Our Bank)
- Multiple Choice
- Delivery
- Online proctored or at a Pearson VUE test centre
- Validity
- Does not expire
Practice Questions
Free Identity-and-Access-Management-Architect Practice Questions
Each question shows the correct answer and an explanation of why it is right
VA
ValidExamDumps Editorial Team
Every question and its answer is checked by our Identity-and-Access-Management-Architect exam
preparation team, who also write the explanation shown with each one.
How we research and review these pages
Universal containers wants to implement SAML SSO for their internal salesforce users using a third-party IDP. After some evaluation, UC decides not to set up my domain for their salesforce.org. How does that decision impact their SSO implementation?
Correct Answer:
D
Explanation
Dynamic branding in Experience Cloud requires two specific technical implementations. First, the site must be built using the Customer Account Portal template, which is the only template that supports dynamic branding features. Second, you need to pass either an experience ID (expid) or a placeholder parameter in the URL to tell Salesforce which brand configuration to apply. Without both pieces in place, dynamic branding during login won't function. Other templates and approaches won't give you the same capability.
Northern Trail Outfitters want to allow its consumer to self-register on it business-to-consumer (B2C) portal that is built on Experience Cloud. The identity architect has recommended to use Person Accounts.
Which three steps need to be configured to enable self-registration using person accounts?
Choose 3 answers
Correct Answer:
A, C, D
Explanation
When customers can't self-register but need to set their own passwords after access is granted, there are two valid approaches. You can use the API to update Experience Cloud site membership and trigger password reset, which works well for programmatic scenarios. Alternatively, Login Flows let you configure the password reset directly in the user experience itself, making it part of the login journey. Both solutions fulfill the requirement without requiring manual password management by administrators.
Northern Trail Outfitters (NTO) believes a specific user account may have been compromised. NTO inactivated the user account and needs U perform a forensic analysis and identify signals that could Indicate a breach has occurred.
What should NTO's first step be in gathering signals that could indicate account compromise?
Correct Answer:
D
Explanation
The OAuth 2.0 Web Server Flow requires understanding three core concepts. The Client Secret is essential because the application must prove its identity to Salesforce when exchanging the authorization code. An Access Token is what you receive after successful authentication and is used to call APIs on behalf of the user. Scopes define what permissions the application is requesting, limiting what the token can do. Refresh tokens are used in other flows but not typically in Web Server Flow, and Grant Type describes the overall pattern rather than being part of the individual flow mechanics.
A division of a Northern Trail Outfitters (NTO) purchased Salesforce. NTO uses a third party identity provider (IdP) to validate user credentials against Its corporate Lightweight Directory Access Protocol (LDAP) directory. NTO wants to help employees remember as passwords as possible.
What should an identity architect recommend?
Correct Answer:
A
Explanation
Delegated Authentication is a feature that lets Salesforce outsource authentication to external services. It can connect to both SOAP and REST services, giving you flexibility in how you integrate with your backend authentication system. It can also be assigned through Permission Sets, allowing you to control which users must use delegated authentication and which can use standard Salesforce authentication. However, it's not a multi-factor authentication mechanism and can't modify user attributes directly.
Universal containers wants salesforce inbound Oauth-enabled integration clients to use SAML-BASED single Sign-on for authentication. What Oauth flow would be recommended in this scenario?
Correct Answer:
B
Explanation
To ensure only active Salesforce users access the order tracking system, you need to establish Salesforce as an identity provider. This allows Salesforce to vouch for users who are already authenticated within your Salesforce instance. The order tracking system then trusts Salesforce's SAML assertions about user identity and active status. Setting up the corporate identity store as an IdP would bypass Salesforce entirely and defeat the purpose of controlling access through Salesforce. The requirement specifically mentions the system should be visible within Salesforce, reinforcing that Salesforce should be the IdP.
Universal Containers (UC) wants to use Salesforce for sales orders and a legacy of system for order fulfillment. The legacy system must update the status of orders in 65* Salesforce in real time as they are fulfilled. UC decides to use OAuth for connecting the legacy system to Salesforce. What OAuth flow should be considered that doesn't require storing credentials, client secret or refresh tokens?
Correct Answer:
B
Explanation
When rolling out mobile apps while maintaining IP restrictions, you need to relax those restrictions specifically for the mobile application. The Connect App settings for Salesforce1 allow you to modify IP restrictions at the app level rather than globally. Adding a second factor of authentication, such as multi-factor authentication, provides the security compensation needed when you're allowing access from any location. This approach keeps your core IP restrictions intact for other scenarios while enabling mobile productivity. Other solutions like VPN requirements wouldn't meet the anywhere access requirement.
Full Access
Get the complete Identity-and-Access-Management-Architect question set
- 248 questions covering all exam domains
- Correct answers with explanations, like the free questions above
- PDF and online practice test
- 90 days of free updates
Domain 1: Identity Management Concepts:
17%
Understand common authentication patterns and the differences between each one. Learn the building blocks of identity solutions, how trust is established between systems, and how to recommend appropriate user provisioning methods and troubleshoot single sign-on failures.
Domain 2: Accepting Third-Party Identity in Salesforce:
21%
Identify when Salesforce acts as a Service Provider and how to provision users from identity stores in B2E and B2C scenarios. Choose appropriate authentication mechanisms, enable SSO with access rights, and use auditing and monitoring tools to diagnose identity provider issues.
Sample question from this domain above:
Q4
Domain 3: Salesforce as an Identity Provider:
17%
Select the appropriate OAuth flow for different scenarios and recommend scope and configuration for connected apps. Understand OAuth implementation concepts including tokens, refresh tokens, expiration, and revocation, and identify the right Salesforce technologies to provide identity to third-party systems.
Sample questions from this domain above:
Q3Q5
Domain 4: Access Management Best Practices:
15%
Determine the most appropriate multi-factor authentication methods and session types for given requirements. Learn how to assign and maintain roles, profiles, and permission sets during SSO, and apply tools to audit user activity during and after login.
Sample question from this domain above:
Q6
Domain 5: Salesforce Identity:
12%
Identify the role of Identity Connect in Salesforce Identity implementations. Understand how Salesforce Customer 360 Identity fits into a fully developed Customer 360 solution and recommend appropriate Salesforce license types for specific requirements.
Domain 6: Community (Partner and Customer):
18%
Describe customization capabilities in Experience Cloud including branding, authentication options, identity verification, and password reset. Determine how to support external identity providers in communities, understand external identity solutions and licensing, and identify when to use embedded login.
Sample questions from this domain above:
Q1Q2
FAQ
Identity-and-Access-Management-Architect Exam FAQ
Common questions about the exam itself
What background do I need before taking the Platform Identity and Access Management Architect exam?
You need solid experience with Salesforce identity features, single sign-on flows, and OAuth concepts. Most candidates come from technical architect, identity specialist or senior developer roles with hands-on experience implementing SSO, managing user provisioning, and integrating third-party identity providers into Salesforce environments.
How long should I spend preparing for this exam?
Plan for 8 to 16 weeks of preparation depending on your background with identity and access management. If you're new to IAM concepts, you may need the full 16 weeks. If you already have solid Salesforce platform knowledge and some identity experience, you might complete it in 8 to 10 weeks.
Which objective area is typically the hardest for candidates?
Access Management Best Practices tends to be challenging because it requires understanding subtle security trade-offs rather than just memorizing definitions. Session management, multi-factor authentication impacts, and the interplay between profiles, permission sets, and roles during SSO require scenario-based thinking rather than simple recall.
What's the passing score for the Platform Identity and Access Management Architect exam?
You need to score 67 percent to pass, which means getting approximately 40 out of 60 questions correct.
How does this certification fit within the Salesforce Architect track?
This is a specialized architect certification that sits alongside other platform architect certifications like the Data Architect and Application Architect. You should typically complete the System Administrator and Platform App Builder certifications first, then move to a platform architect certification that matches your specialty.
Does the Platform Identity and Access Management Architect certification expire?
No, this certification does not expire once you pass it. Unlike many other Salesforce certifications that require renewal, the Identity and Access Management Architect credential remains valid indefinitely.
What happens if I fail the exam? What are the retake rules?
You must wait 24 hours before scheduling your first retake. After your second attempt, you must wait 14 days before scheduling another retake. The retake fee is USD 200, which is 50 percent of the initial USD 400 exam cost.
Can I take this exam online or do I need to go to a test centre?
You can take the exam either online with remote proctoring from your home or office, or at a Pearson VUE testing centre. You choose which delivery method suits you best when you register.
What job roles is this certification designed for?
The certification targets architects, senior developers, and identity specialists who lead identity strategy, manage user access across the Salesforce platform, and integrate third-party identity providers. It also suits technical architects responsible for designing SSO solutions and security infrastructure for enterprise Salesforce deployments.
Is this exam scenario-based or does it test pure memorization?
This exam is heavily scenario-based. Most questions present a business requirement or technical problem and ask you to choose the best approach. You need to understand when to use each feature, not just know what it is, especially for OAuth flows, provisioning strategies, and federation options.