ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

Your organization is integrating a partner's SaaS application. Users should authenticate with corporate Active Directory credentials and gain seamless access without storing passwords at the provider. The design must allow the provider to rely on assertions issued by your identity provider and include role attributes for authorization decisions. Which federated identity pattern best satisfies these requirements?

  • OpenID Connect implicit flow using the SaaS provider as identity provider

  • Site-to-site VPN allowing the provider to bind directly to on-premises LDAP

  • SAML 2.0 Web Browser Single Sign-On with AD FS acting as the identity provider

  • OAuth 2.0 Resource Owner Password Credentials grant to the SaaS application

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Architecture and Design
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot