
EC-CouncilCloud Security Essentials
Domain 2Objective 3
Identity Federation and Single Sign-On (SSO) CSE Practice Questions (Page 5)
Part of the Identity and Access Management in the Cloud domain, which makes up ~12% of our current practice bank.
44questions here
9free pages
6concepts
Questions 21–25
- 21
A security team is investigating a potential SSO vulnerability. They suspect an attacker could replay a captured SAML assertion to gain access to a cloud application. Which control is most effective at preventing assertion replay?
Select an answer first - 22
Which federation standard is most commonly used for browser-based single sign-on across enterprise applications and is based on XML?
Select an answer first - 23
A company is integrating its cloud provider's identity service with an external IdP for SSO. The company has a strict requirement that all authentication must be done by the external IdP, and the cloud provider must not store any user passwords. Which integration approach satisfies this requirement?
Select an answer first - 24
A company is federating its on-premises Active Directory with a cloud SaaS application. The SaaS application supports both SAML 2.0 and OpenID Connect. The company's security policy requires that the federation protocol support multifactor authentication (MFA) enforcement at the IdP and allow the SaaS application to receive user attributes such as department and role. Which protocol should the company choose?
Select an answer first - 25
A company is integrating its on-premises Active Directory with a cloud SaaS application via SAML federation. The company has a strict security policy that requires all authentication to be challenged with MFA, and they want to minimize the number of systems that handle user credentials. Which architecture best meets these requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.