ISC2 Certified Cloud Security Professional (CCSP) Practice Question
A multinational corporation is integrating a new SaaS-based HR platform with its corporate identity provider using SAML 2.0. Security policy mandates multi-factor authentication (MFA) for all remote users. However, inside the company's secure data centers, carrying smartphones is prohibited by physical security rules, so mobile OTP applications are not an option. Which IAM design best satisfies both requirements without degrading user experience?
Require all users to enroll in a push-based authenticator mobile app and prompt for approval during each login
Deploy adaptive MFA that issues hardware FIDO2 security keys to on-site personnel while remote users continue to use time-based one-time passwords (TOTP) from a mobile authenticator app
Increase password complexity rules to 15 characters and rotate every 60 days, eliminating the need for second factors
Restrict access to the HR application by source IP addresses and rely on SAML single sign-on with passwords only
The most practical solution is to use an adaptive MFA approach that supports multiple authenticators. By issuing hardware-based FIDO2 security keys to personnel who cannot bring phones into secure areas, the organization provides a possession factor that works without a mobile device. Remote users can continue using TOTP apps, meeting the company's MFA mandate. Requiring push-based mobile authenticators would violate the no-phone rule for on-site staff, while password complexity or IP restrictions alone do not constitute MFA and therefore fail the policy requirement.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is SAML 2.0 and how does it support identity management?
Open an interactive chat with Bash
What is adaptive MFA and why is it important?
Open an interactive chat with Bash
What are FIDO2 security keys and how do they enhance MFA?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Application Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .