ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During integration of a new SaaS HR application with the organization's SAML 2.0 single sign-on service, testing reveals that intercepted SAML assertions remain usable for nearly eight hours-their default lifetime. Which configuration change on the identity provider and service provider will most effectively reduce this replay risk while still allowing seamless SSO for legitimate users?
Allow only identity-provider-initiated SSO so users never reach the SaaS login page.
Remove the AudienceRestriction element so the same assertion can be reused across multiple SaaS applications without additional logins.
Include the user's password hash in the assertion attributes so the service provider can perform local authentication.
Configure both parties to issue and accept only signed assertions that expire within a few minutes of issuance.
Replay attacks succeed when an attacker reuses a previously issued SAML assertion that is still within its validity period. The most effective countermeasure is to shorten that period and ensure each assertion is cryptographically signed, allowing the service provider to verify integrity and reject any assertion presented outside the very small NotOnOrAfter window. This makes captured assertions useless within minutes. Switching to IdP-initiated flows, sending password hashes, or removing AudienceRestriction do not address assertion replay and in fact introduce new security weaknesses or reduce assurance.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a SAML assertion?
Open an interactive chat with Bash
How does signing a SAML assertion improve security?
Open an interactive chat with Bash
What is the NotOnOrAfter window in SAML, and why is it important?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Concepts
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .