Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Security Architecture and Design

Domain 1Objective 3

Federated Access and SSO GCAD Practice Questions (Page 10)

Part of the Identity and Access Management domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 3–5 from this objective — we provide 60 practice questions to prepare you well beyond it. (estimate)

60questions here
12free pages
15concepts

Questions 46–50

  1. 46application · medium

    A company is integrating its corporate IdP with a new SaaS application using SAML 2.0. The SaaS application is the service provider (SP). Which of the following responsibilities belongs to the SP in this federation?

    Select an answer first
  2. 47expert · medium

    A security team is reviewing the OAuth 2.0 implementation of a third-party application that integrates with their corporate identity provider. The application uses the authorization code flow and stores the client secret in its source code. An attacker gains access to the source code repository and extracts the client secret. Which of the following is the most effective mitigation to limit the impact of this compromise?

    Select an answer first
  3. 48foundation · easy

    In a JWT, what is a 'claim'?

    Select an answer first
  4. 49foundation · easy

    What is the role of the OASIS standard in identity federation?

    Select an answer first
  5. 50foundation · easy

    In a federated trust relationship, what is the primary responsibility of the identity provider (IdP)?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCAD” is a trademark of its owner, used for identification only.