Salesforce Plat-Arch-203 試験概要:
| 認定ベンダー: | Salesforce |
| 試験名: | Salesforce認定プラットフォーム アイデンティティ・アクセス管理アーキテクト |
| 試験番号: | Plat-Arch-203 |
| 認定の有効期間: | 2年間 |
| 試験形式: | 単一選択式, 複数選択式, シナリオ設問 |
| 対応言語: | 英語, 日本語 |
| 関連資格: | Salesforce認定システムアーキテクト Salesforce認定アプリケーションアーキテクト |
| 試験時間: | 105 - 120 |
| 出題数: | 60 - 65 |
| 合格点: | 67% |
| 受験料: | 400米ドル(初回受験)、200米ドル(再受験) |
| 推奨トレーニング: | アーキテクト向け学習コース:アイデンティティ・アクセス管理 |
| 受験申し込み: | Salesforce認定資格試験の登録手続き |
| サンプル問題: | Salesforce Plat-Arch-203 サンプル問題 |
| 受験方法: | オンライン監督付き受験、またはKryterion社もしくはPearson VUE社の試験会場での受験を選択できます。 |
| 前提条件: | 受験に必須の前提条件は設けられていません。推奨される条件として、Salesforce環境でのアイデンティティ・アクセス管理に関する実務経験2~3年、SAML/OAuth/OIDCに関する知識、または他のアーキテクト認定資格の保有が挙げられます。 |
| 公式シラバスのURL: | https://trailhead.salesforce.com/credentials/identityandaccessmanagementarchitect |
Salesforce Plat-Arch-203 試験シラバストピック:
| セクション | 比重 | 目標 |
|---|---|---|
| トピック 1: コミュニティ(パートナー向け・顧客向け)のアイデンティティ管理 | 18% | - ユーザー自身による登録とパスワードのリセット - コミュニティ向け外部アイデンティティプロバイダーとの連携 - Experience Cloudにおける認証と本人確認 |
| トピック 2: アクセス管理のベストプラクティス | 15% | - ロール階層と共有ルールの設定 - 多要素認証とセッション管理 - 項目レベルおよびオブジェクトレベルのセキュリティ - プロファイル、権限セット、グループの管理 |
| トピック 3: アイデンティティプロバイダーとしてのSalesforce | 19% | - SCIMによる外部システムへのユーザープロビジョニング - 接続アプリケーションとOAuthフロー
|
| トピック 4: アイデンティティ管理の基本概念 | 17% | - 認証方式の類型と選定基準
|
| トピック 5: Salesforceにおける第三者アイデンティティの受け入れ | 26% | - 認証プロバイダーとソーシャルログイン - Just-in-Time(JIT)プロビジョニング - SAML SSOの設定とトラブルシューティング
|
| トピック 6: Salesforceアイデンティティの活用 | 12% | - Customer 360 Identityとの連携統合 - アイデンティティの利用形態に応じたライセンス種別の選定 - Identity Connectの導入と実装 |
Salesforce Certified Platform Identity and Access Management Architect 認定 Plat-Arch-203 試験問題:
1. A financial enterprise is planning to set up a user authentication mechanism to login to the Salesforce system. Due to regulatory requirements, the CIO of the company wants user administration, including passwords and authentication requests, to be managed by an external system that is only accessible via a SOAP webservice.
Which authentication mechanism should an identity architect recommend to meet the requirements?
A) Just-in-Time Provisioning
B) Identity Connect
C) OAuth Web-Server Flow
D) Delegated Authentication
2. Universal Containers (UC) has an e-commerce website where customers can buy products, make payments and manage their accounts. UC decides to build a Customer Community on Salesforce and wants to allow the customers to access the community from their accounts without logging in again. UC decides to implement an SP-initiated SSO using a SAML-compliant Idp. In this scenario where Salesforce is the Service Provider, which two activities must be performed in Salesforce to make SP-initiated SSO work? Choose 2 answers
A) Configure SAML SSO settings.
B) Set up My Domain.
C) Create a Connected App.
D) Configure Delegated Authentication.
3. Northern Trail Outfitters wants to implement a partner community. Active community users will need to review and accept the community rules, and update key contact information for each community member before their annual partner event.
Which approach will meet this requirement?
A) Add a banner to the community Home page asking users to update their profile and accept the new community rules.
B) Create tasks for users who need to update their data or accept the new community rules.
C) Create a login flow that conditionally prompts users who have not accepted the new community rules and who have missing or outdated information.
D) Create a custom landing page and email campaign asking all community members to login and verify their data.
4. Northern Trail Outfitters (NTO) wants to give customers the ability to submit and manage issues with their purchases. It is important for NTO to give its customers the ability to login with their Amazon credentials.
What should an identity architect recommend to meet these requirements?
A) Configure a predefined authentication provider for Amazon.
B) Configure an OpenID Connect Authentication Provider for Amazon.
C) Create a custom external authentication provider for Amazon.
D) Configure Amazon as a connected app.
5. How should an Architect force users to authenticate with Two-factor Authentication (2FA) for Salesforce only when not connected to an internal company network?
A) Apply the "Two-factor Authentication for User Interface Logins" permission and Login IP Ranges for all Profiles.
B) Use an Apex Trigger on the UserLogin object to detect the user's IP address and prompt for 2FA if needed.
C) Add the list of company's network IP addresses to the Login Range list under 2FA Setup.
D) Use Custom Login Flows with Apex to detect the user's IP address and prompt for 2FA if needed.
質問と回答:
| 質問 # 1 正解: D | 質問 # 2 正解: A、B | 質問 # 3 正解: C | 質問 # 4 正解: B | 質問 # 5 正解: D |














1233 お客様のコメント
品質保証JPexamはIT認定試験のシラバスに従って、試験問題の範囲を正確に絞って、的中率が99%の最新問題集を捧げます。
1年間の無料更新サービスJPexamは1年以内に問題集の無料更新サービスを提供し、お客様がいつでも最新版の問題集を持つことを保証いたします。もし試験の内容が変更されたら、弊社は直ちにお客様にお知らせします。それに、弊社の問題集が更新されたら、早速メールで最新バージョンを送付いたします。
全額返金JPexamの問題集を利用すると、短時間で勉強しても試験に合格できるのを保証いたします。試験に不合格になってしまった場合、弊社は全額返金いたします。(
ご購入前のお試しJPexamは問題集のサンプルを無料で提供いたします。ご購入前にサンプルを試用して製品の品質を確認することができます。ご遠慮なく利用してください。
