🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 11 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your company hosts an internal HTTPS web application on Amazon EC2 instances behind an Application Load Balancer. Employees already use Azure AD for authentication. Security wants to add single sign-on so users can access the application with their corporate credentials, leverage Azure AD conditional access, and avoid any modification to the application code. Session lifetime must be limited to 1 hour. Which solution best satisfies these requirements?

  • Deploy a Keycloak cluster on EC2, federate it with Azure AD through SAML, and re-implement the application's login flow to act as a SAML service provider.

  • Create an Amazon Cognito user pool, establish SAML federation with Azure AD, and update the application to validate Amazon Cognito JWT access tokens.

  • Enable AWS IAM Identity Center, configure Azure AD as a SAML 2.0 IdP, and have the Application Load Balancer trust Identity Center to authenticate users.

  • Configure an authentication action on the Application Load Balancer listener that uses Azure AD as an external OpenID Connect IdP, setting the client ID, client secret, discovery URL, and a 3,600-second session cookie.

ISC2 Systems Security Certified Practitioner (SSCP)
Access Controls
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot