
GIAC Cloud Security Architecture and Design
Domain 1Objective 3
Federated Access and SSO GCAD Practice Questions (Page 11)
Part of the Identity and Access Management domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 3–5 from this objective — we provide 60 practice questions to prepare you well beyond it. (estimate)
60questions here
12free pages
15concepts
Questions 51–55
- 51
A developer is implementing OpenID Connect for a web application. The application receives an ID token from the identity provider. Which of the following is the primary purpose of the ID token?
Select an answer first - 52
What is the primary purpose of single sign-on (SSO)?
Select an answer first - 53
How are sessions typically managed between the IdP and SP in an SSO environment?
Select an answer first - 54
In a SAML 2.0 web-based SSO flow, what is the role of the service provider (SP)?
Select an answer first - 55
A company is integrating a new SaaS application that supports SAML 2.0. The company's identity team has configured the IdP to send a SAML assertion to the SaaS application. The SaaS application is rejecting the assertion with a signature validation error. The team has verified that the assertion is correctly signed and the certificate is valid. What is the most likely cause of the issue?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCAD” is a trademark of its owner, used for identification only.