
EC-CouncilCloud Security Essentials
Domain 2Objective 3
Identity Federation and Single Sign-On (SSO) CSE Practice Questions (Page 7)
Part of the Identity and Access Management in the Cloud domain, which makes up ~12% of our current practice bank.
44questions here
9free pages
6concepts
Questions 31–35
- 31
A company is troubleshooting an SSO failure. Users can authenticate at the IdP, but the SaaS application rejects the SAML assertion with an 'Invalid audience' error. What is the most likely cause?
Select an answer first - 32
When integrating a cloud provider's identity service with an external IdP for SSO, what is typically required to establish the trust?
Select an answer first - 33
A company uses AWS IAM Identity Center (successor to AWS SSO) and wants to give users access to multiple AWS accounts using their existing corporate credentials from Microsoft Entra ID. Which integration approach is correct?
Select an answer first - 34
A company is planning to implement SSO for its employees. The security team wants to ensure that if an employee leaves the company, their access to all cloud applications is revoked as quickly as possible. Which SSO implementation approach best supports this requirement?
Select an answer first - 35
What is the purpose of configuring a cloud provider as a service provider (SP) in a federation with an external IdP?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.