🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 11 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

A development team is building a customer-facing web application on AWS. Corporate security policy requires users to authenticate through a third-party OpenID Connect (OIDC) provider; the app must receive a cryptographically signed token containing user profile claims for personalization; and backend APIs will validate the token's signature by retrieving the provider's JSON Web Key Set (JWKS). Which OIDC flow best satisfies these requirements while following current best practice?

  • Use the OIDC Authorization Code flow so the application exchanges an authorization code at the token endpoint and receives a signed ID token containing user profile claims.

  • Use the OIDC Implicit flow so the browser receives an unsigned access token that the backend forwards to the APIs.

  • Use the OAuth 2.0 Resource Owner Password Credentials grant so the application can obtain a refresh token and store the user's password for reuse.

  • Use the OAuth 2.0 Client Credentials grant so the backend requests an opaque bearer token directly from the identity provider.

ISC2 Systems Security Certified Practitioner (SSCP)
Access Controls
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot