
EC-CouncilCloud Security Essentials
Domain 2Objective 3
Identity Federation and Single Sign-On (SSO) CSE Practice Questions (Page 2)
Part of the Identity and Access Management in the Cloud domain, which makes up ~12% of our current practice bank.
44questions here
9free pages
6concepts
Questions 6–10
- 6
A company is choosing between SAML 2.0 and OpenID Connect for a new SSO implementation. The company has a mix of legacy web applications and modern mobile apps. The legacy apps require server-side sessions, while the mobile apps need to call APIs. Which protocol strategy best meets both requirements?
Select an answer first - 7
A company uses Okta as its identity provider (IdP) and wants employees to access a third-party SaaS application that acts as a service provider (SP). The SaaS application requires SAML 2.0 for federation. The administrator has already configured the trust relationship in Okta. What must the administrator do next to complete the federation setup?
Select an answer first - 8
An organization is implementing SSO with an external IdP. They have two applications: App A supports SAML, and App B supports OIDC. The organization wants to minimize the risk of token replay attacks. Which configuration is most effective?
Select an answer first - 9
A company is integrating its cloud provider's identity service (e.g., AWS IAM Identity Center) with an external IdP for SSO. The company has multiple AWS accounts and wants to allow users to access resources in all accounts without re-authenticating. What is the recommended way to achieve this?
Select an answer first - 10
A company is federating its on-premises IdP with a cloud provider's identity service. The cloud provider requires that the IdP's metadata be publicly accessible. The company is concerned about exposing internal details. What is the best way to address this concern?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.