A high-quality, authoritative exam is a long and tough climb — especially when your calendar is already full. TestValid respects that reality: the Identity-and-Access-Management-Architect bank delivers 112 expert-verified practice questions covering the Salesforce Certified Identity and Access Management Architect objectives, built for professionals short on time.
Salesforce Identity-and-Access-Management-Architect Exam Overview:
| Certification Vendor: | Salesforce |
|---|---|
| Exam Name: | Salesforce Certified Identity and Access Management Architect |
| Exam Number: | Identity-and-Access-Management-Architect |
| Exam Duration: | 120 minutes |
| Certificate Validity Period: | Maintenance required with each release cycle |
| Exam Price: | USD 400 |
| Real Exam Qty: | 60 |
| Passing Score: | 67% |
| Exam Format: | Multiple select, Multiple choice |
| Available Languages: | English |
| Related Certifications: | Salesforce Certified Technical Architect |
| Sample Questions: | ![]() |
| Exam Way: | Online proctored or Onsite testing center |
| Pre Condition: | Salesforce Certified Administrator or equivalent experience |
| Official Syllabus URL: | https://trailhead.salesforce.com/en/credentials/identityaccessmanagementarchitect |
Salesforce Identity-and-Access-Management-Architect Exam Syllabus Topics:
| Section | Objectives |
|---|---|
| Access Management | - Given a scenario, describe how to configure access management
|
| Single Sign-On (SSO) | - Given a scenario, recommend the appropriate SSO strategy
|
| Identity Management | - Given a scenario, recommend the appropriate Salesforce authentication mechanism
|
| Directory Services | - Given a scenario, recommend the appropriate directory service solution
|
Identity-and-Access-Management-Architect Exam Facts for Busy Professionals
According to the latest exam information, the Identity-and-Access-Management-Architect exam contains 60 questions and runs for 120 minutes minutes. Simulating that exact limit in practice builds the pacing a tough exam demands.
The Salesforce Certified Identity and Access Management Architect blueprint centers on these domains:
- Access Management
- Identity Management
- Directory Services
Further domains complete the official outline — the question bank covers every one.
Clear terms, no runaround. If you fail the corresponding exam within 60 days of purchase, send us a scanned copy of your enrollment slip and your official Score Report PDF within two days of the exam date; verified claims are refunded in full within seven days. Exclusions: exams taken within three days of purchase, candidate names that do not match the payer, and free or expired products. Prefer to switch tracks? Exchange your product for two others of equal value at no cost.
A team of IT experts and certified trainers with rich experience in the Salesforce Certified Identity and Access Management Architect field writes it — and keeps it honest. Every answer is expert-verified, the content is checked continuously for updates, and each new Identity-and-Access-Management-Architect version is emailed to you free for 365 days. Compared with training institutions, the bank is affordable and self-paced; compared with guesswork, it is systematic. Download the free demo first, and if anything goes wrong — even a simple downloading problem — 24/7 customer assistance is one message away.
Salesforce states the following prerequisites for the Salesforce Certified Identity and Access Management Architect: Salesforce Certified Administrator or equivalent experience.
Confirm the current requirements on the official certification page before you register.
Currently, the Identity-and-Access-Management-Architect exam requires a passing score of 67%, with a registration fee of USD 400. Salesforce sets both figures, so verify the latest on the official site before scheduling.
Upon successful payment, our system automatically sends the product to your mailbox — typically within about a minute — with an instant download link on screen. If nothing arrives within two hours, check your spam folder and contact our 24/7 customer assistance. Updates are free for 365 days: the moment a new version releases, the latest bank is sent to your email immediately, no matter when you purchased. A 50% renewal discount applies when the period ends.
Salesforce Certified Identity and Access Management Architect Sample Questions:
A global fitness equipment manufacturer uses Salesforce to manage its sales cycle. The manufacturer has a custom order fulfillment app that needs to request order data from Salesforce. The order fulfillment app needs to integrate with the Salesforce API using OAuth 2.0 protocol.
What should an identity architect use to fulfill this requirement?
- A. Connected App and OAuth Scopes
- B. Genre Age Integration
- C. OAuth Token
- D. Authentication Providers
Correct Answer: A 🗳️
Explanation: Only visible for TestValid members. You can sign-up / login (it's free).
An administrator created a connected app for a custom web application in Salesforce which needs to be visible as a tile in App Launcher. The tile for the custom web application is missing in the app launcher for all users in Salesforce. The administrator requested assistance from an identity architect to resolve the issue.
Which two reasons are the source of the issue?
Choose 2 answers
- A. Statutes, for the connected app is not set in Connected App settings.
- B. Obtain scope does not include "openid".
- C. The connected app is not set in the App menu as "Visible in App Launcher".
- D. Session Policy is set as "High Assurance Session required" for this connected app.
Correct Answer: A,C 🗳️
Explanation: Only visible for TestValid members. You can sign-up / login (it's free).
A global fitness equipment manufacturer is planning to sell fitness tracking devices and has the following requirements:
1) Customer purchases the device.
2) Customer registers the device using their mobile app.
3) A case should automatically be created in Salesforce and associated with the customers account in cases where the device registers issues with tracking.
Which OAuth flow should be used to meet these requirements?
- A. OAuth 2.0 SAVL Server Assertion Flow
- B. OAuth 2.0 User-Agent Flow
- C. OAuth 2.0 Device Flow
- D. OAuth 2.0 Asset Token Flow
Correct Answer: D 🗳️
Explanation: Only visible for TestValid members. You can sign-up / login (it's free).
An identity architect ' s client has a homegrown identity provider (IdP). Salesforce is used as the service provider (SP). The head of IT is worried that during a SP initiated single sign-on (SSO), the Security Assertion Markup Language (SAML) request content will be altered.
What should the identity architect recommend to make sure that there is additional trust between the SP and the IdP?
- A. Ensure that there is an HTTPS connection between IDP and SP.
- B. Ensure that the Issuer and Assertion Consumer Service (ACS) URL is properly configured between SP and IDP.
- C. Encrypt the SAML Request using certification authority (CA) signed certificate and decrypt on IdP.
- D. Ensure that on the SSO settings page, the " Request Signing Certificate " field has a selfsigned certificate.
Correct Answer: D 🗳️
Explanation: Only visible for TestValid members. You can sign-up / login (it's free).
Universal Containers is creating a mobile application that will be secured by Salesforce Identity using the OAuth 2.0 user-agent flow. Application users will authenticate using username and password. They should not be forced to approve API access in the mobile app or reauthenticate for 3 months.
Which two connected app options need to be configured to fulfill this use case?
Choose 2 answers
- A. Set the Refresh Token Policy to expire refresh token after 3 months.
- B. Set the Sealston Timeout value to 3 months.
- C. Set Permitted Users to " All users may self-authorize " .
- D. Set Permitted Users to " Admin approved users are pre-authorized " .
Correct Answer: A,D 🗳️
Explanation: Only visible for TestValid members. You can sign-up / login (it's free).






