Valid Identity-and-Access-Management-Architect Dumps shared by EduDump.com for Helping Passing Identity-and-Access-Management-Architect Exam! EduDump.com now offer the newest Identity-and-Access-Management-Architect exam dumps, the EduDump.com Identity-and-Access-Management-Architect exam questions have been updated and answers have been corrected get the newest EduDump.com Identity-and-Access-Management-Architect dumps with Test Engine here:
A global company has built an external application that uses data from its Salesforce org via an OAuth 2.0 authorization flow. Upon logout, the existing Salesforce OAuth token must be invalidated. Which action will accomplish this?
Correct Answer: A
Salesforce supports token revocation through the revoke token endpoint. When an external application logs the user out and the existing OAuth token must be invalidated immediately, the application should make the appropriate HTTP request to that revocation endpoint and include the current token. That explicitly tells Salesforce the token should no longer be accepted. Requesting a new refresh token or calling unrelated endpoints would not invalidate the existing authorization. Single Logout can help in federated browser journeys, but the requirement here is specifically about invalidating the OAuth token itself. The architecture distinction is important: session logout and token revocation are related but not identical operations, and Salesforce provides a dedicated endpoint for revocation. This is why option A is the best answer in Salesforce terms.