ISC2 Certified Cloud Security Professional (CCSP) Practice Question
Your organization is onboarding a new Software-as-a-Service (SaaS) HR platform that supports SAML 2.0 single sign-on. The plan is to use the company's on-premises Active Directory Federation Services (AD FS) as the identity provider (IdP) so employees can authenticate with their existing domain credentials. Before the SaaS vendor (the service provider) will accept SAML authentication assertions from your IdP, each side must have a mechanism to verify the integrity and origin of those assertions. Which item must the two parties exchange and store to establish this federated trust?
A shared OAuth 2.0 client secret configured on both sides
The LDAP bind username and password for each user account
The identity provider's public X.509 certificate that is used to sign SAML assertions
A pre-shared symmetric encryption key for securing the SAML response
In SAML 2.0 federations, the IdP digitally signs each assertion with its private key so the service provider can verify that the assertion really came from the trusted IdP and was not altered in transit. To enable this verification, the IdP distributes its corresponding public X.509 certificate-usually embedded in SAML metadata-which the service provider imports and stores. The certificate allows the service provider to validate the digital signature on every assertion. A pre-shared symmetric key is not used for signing SAML messages; user LDAP credentials are never shared with a service provider; and an OAuth client secret applies to OAuth/OIDC flows, not to SAML federation.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
How does SAML 2.0 work in federated authentication?
Open an interactive chat with Bash
What is an X.509 certificate, and how is it used in SAML authentication?
Open an interactive chat with Bash
Why is a symmetric key not suitable for SAML message signing?
Open an interactive chat with Bash
Can you explain what an X.509 certificate is?
Open an interactive chat with Bash
What role does AD FS play in a SAML configuration?
Open an interactive chat with Bash
What is the difference between SAML and OAuth?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Application Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .