New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Salesforce Certified B2C Solution Architect (Arch-302) Exam - Topic 3 Question 97 Discussion

Actual exam question for Salesforce's Salesforce Certified B2C Solution Architect (Arch-302) exam
Question #: 97
Topic #: 3
[All Salesforce Certified B2C Solution Architect (Arch-302) Questions]

A nonprofit organization uses Experience Cloud for members who would like to set up recurring donations. They integrate with an external payment gateway and want to make sure to offer the utmost security for their members. They also use Pardot for personalized communications, to ensure members have access to the most meaningful content and messages related to their donation history.

Which three options can a Solution Architect recommend to increase security for their existing users?

Choose 3 answers

Show Suggested Answer Hide Answer
Suggested Answer: A, B, E

Experience Cloud is a product that allows creating and managing digital experiences for customers, partners, employees, and communities. Experience Cloud can be integrated with external payment gateways and Pardot to offer secure and personalized experiences for members who want to set up recurring donations. To increase security for their existing users, a Solution Architect can recommend the following options:

Implement high-assurance requirements for Experience Cloud profiles. High-assurance requirements are settings that define the level of security and identity verification needed for users to access certain pages or features in Experience Cloud. High-assurance requirements can help prevent unauthorized or fraudulent access to sensitive or confidential data or transactions, such as recurring donations.

Add a login flow that defines the scope of user access authorized by authentication providers. A login flow is a process that allows customizing the user login experience in Experience Cloud using various actions, such as collecting information, displaying messages, updating records, etc. A login flow can help define the scope of user access authorized by authentication providers, such as social media accounts or SAML-based identity providers. This can help limit or restrict the access of users based on their authentication method or credentials.

Develop login flows to change the user's session security level to initiate third-party identity verification. A session security level is a setting that determines the level of security and identity verification required for a user's session in Experience Cloud. A session security level can be changed using login flows to initiate third-party identity verification, such as SMS verification, email verification, biometric verification, etc. This can help enhance the security and trust of the user's session and prevent unauthorized or fraudulent access to sensitive or confidential data or transactions, such as recurring donations.

Option C is incorrect because replacing Pardot with Marketing Cloud to implement SMS for multi-factor authentication is not a valid or feasible option to increase security for their existing users. Pardot is a product that allows creating and managing B2B marketing campaigns and activities, such as email marketing, lead generation, lead nurturing, etc. Marketing Cloud is a product that allows creating and managing B2C marketing campaigns and activities, such as email marketing, mobile marketing, social media marketing, etc. Replacing Pardot with Marketing Cloud would not only be costly and complex, but also unnecessary and irrelevant for their use case of setting up recurring donations. Moreover, implementing SMS for multi-factor authentication does not require replacing Pardot with Marketing Cloud, as it can be done using other methods or tools, such as login flows or third-party identity verification services. Option D is incorrect because maintaining GAuth tokens for existing Experience Cloud profiles is not an option or a way to increase security for their existing users. GAuth tokens are tokens that are used by Google Authenticator, an app that generates one-time passwords for two-factor authentication. GAuth tokens are not related to Experience Cloud profiles or their security settings. Reference:

https://help.salesforce.com/s/articleView?id=sf.networks_security.htm&type=5

https://help.salesforce.com/s/articleView?id=sf.networks_login_flow_examples.htm&type=5

https://help.salesforce.com/s/articleView?id=sf.networks_session_security_levels.htm&type=5


Contribute your Thoughts:

0/2000 characters
Portia
3 days ago
Wow, I didn't know about high-assurance requirements!
upvoted 0 times
...
Lajuana
8 days ago
I disagree with C; Pardot is doing fine for now.
upvoted 0 times
...
Ludivina
13 days ago
A, B, and E are the way to go. Gotta keep those hackers away from the donation money!
upvoted 0 times
...
Zana
18 days ago
Haha, replace Pardot with Marketing Cloud? What is this, a joke? A, B, and E for sure.
upvoted 0 times
...
Billi
24 days ago
I'd go with A, B, and E. Pardot is great, but security has to come first.
upvoted 0 times
...
Rozella
29 days ago
Definitely A, B, and E. Can't be too careful with people's money, you know?
upvoted 0 times
...
Harrison
1 month ago
A, B, and E are the way to go. Gotta keep those donations secure!
upvoted 0 times
...
Monte
1 month ago
Replacing Pardot with Marketing Cloud for SMS sounds like a stretch for security; I thought Pardot had its own security features.
upvoted 0 times
...
Marvel
1 month ago
I practiced a similar question about security measures, and I feel like maintaining GAuth tokens could be important, but I’m not confident about the details.
upvoted 0 times
...
Rosalyn
2 months ago
I think adding a login flow could be a good option since it helps define user access, but I’m not clear on how that integrates with the payment gateway.
upvoted 0 times
...
Minna
2 months ago
I remember discussing high-assurance requirements in class, but I'm not entirely sure how they apply to Experience Cloud profiles specifically.
upvoted 0 times
...
Mi
2 months ago
I think the key here is balancing security with the existing systems they have in place. Implementing high-assurance requirements and maintaining the GAuth tokens seem like good ways to enhance security without major changes to their infrastructure. I'll focus on those options first.
upvoted 0 times
...
Yuriko
2 months ago
I think option A is crucial for security.
upvoted 0 times
...
Lai
2 months ago
A) and B) sound solid for security!
upvoted 0 times
...
Lennie
3 months ago
The login flow options sound promising, especially the one about defining the scope of user access. That could help ensure members only have the permissions they need to manage their donations. I'll make sure to read through those carefully.
upvoted 0 times
...
Reita
3 months ago
I’m not sure about C. Pardot is working fine for us.
upvoted 0 times
...
Alishia
3 months ago
Hmm, I'm a bit confused about the Pardot and Marketing Cloud options. I'm not sure how SMS for multi-factor authentication would fit in here, since the question is about increasing security for the existing users. I'll need to think that one through more.
upvoted 0 times
...
Brittani
3 months ago
I think I'd start by looking at the options that focus on security for the Experience Cloud profiles, since that's where the members are setting up their recurring donations. The high-assurance requirements and maintaining the GAuth tokens seem like good places to focus.
upvoted 0 times
Martina
3 months ago
I agree, high-assurance requirements are crucial for security.
upvoted 0 times
...
...

Save Cancel