
EC-CouncilCloud Security Essentials
Domain 2Objective 3
Identity Federation and Single Sign-On (SSO) CSE Practice Questions (Page 1)
Part of the Identity and Access Management in the Cloud domain, which makes up ~12% of our current practice bank.
44questions here
9free pages
6concepts
Questions 1–5
- 1
A company wants to allow employees to sign in to Microsoft 365 using their existing on-premises Active Directory credentials. They plan to use Azure AD (now Microsoft Entra ID) as the identity provider. Which configuration is required to establish the federation trust?
Select an answer first - 2
A company is building a custom web application that needs to authenticate users via their existing Google accounts and also call Google APIs on behalf of those users. Which protocol should the application use?
Select an answer first - 3
A company uses Microsoft Entra ID (Azure AD) as its cloud identity provider. They want to allow employees to sign in to AWS accounts using their existing corporate credentials. They plan to use AWS IAM Identity Center (successor to AWS SSO) with SAML 2.0 federation. What is the first step they should perform in the integration?
Select an answer first - 4
A security administrator is reviewing the federation trust between the company's IdP and a cloud application. The application is configured to accept assertions from the IdP. During a penetration test, the administrator discovers that the application does not validate the issuer field in the SAML assertion. What is the most likely security impact?
Select an answer first - 5
What is the role of a token in cloud SSO implementation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.