ISC2 Certified Cloud Security Professional (CCSP) Practice Question
Your organization is moving its on-premises HR system to a Software-as-a-Service platform. Users will authenticate through the existing enterprise identity provider with SAML 2.0 federation. Security has two requirements:
HR administrators must be able to create, modify, and disable any employee account.
All other employees must be limited to viewing and updating only their own personal records. Which access-control approach in the SaaS most effectively enforces least privilege while minimizing ongoing administrative effort?
Implement SAML-driven attribute-based access control so the SaaS assigns permissions from user and group attributes in each login assertion.
Enforce multifactor authentication for all users before they access the SaaS portal.
Rely on single sign-on only and manually grant HR administrator rights to specific users inside the SaaS tenant.
Create one shared service account with full administrator rights and give the credentials to the HR department.
Attribute-Based Access Control (ABAC) evaluates subject, resource, action, and environmental attributes received in the SAML assertion (for example, job role = "HR Admin" or employeeID = "12345") against centrally defined policies. The SaaS can therefore grant the provisioning API scope to users whose role attribute equals "HR Admin," while dynamically restricting everyone else to self-service access on resources where the employeeID matches their own identity. Because decisions are made automatically at runtime, ABAC meets the least-privilege requirement without the manual role maintenance implied in the other choices. Simply enabling SSO or MFA does not differentiate privilege levels, and a shared admin account violates both accountability and least-privilege principles.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is SAML 2.0 Federation?
Open an interactive chat with Bash
How does Attribute-Based Access Control (ABAC) work?
Open an interactive chat with Bash
Why is least privilege important in access-control systems?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Concepts, Architecture and Design
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .