
GIAC Cloud Security Architecture and Design
Domain 1Objective 3
Federated Access and SSO GCAD Practice Questions (Page 5)
Part of the Identity and Access Management domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 3–5 from this objective — we provide 60 practice questions to prepare you well beyond it. (estimate)
60questions here
12free pages
15concepts
Questions 21–25
- 21
A company is setting up a new SAML 2.0 federation between its IdP and a SaaS vendor. The vendor has provided its SAML metadata file. What should the IdP administrator do with this metadata to establish the trust relationship?
Select an answer first - 22
A security analyst is reviewing the SAML 2.0 configuration between the company's IdP and a third-party SP. The analyst discovers that the SP does not validate the signature on the SAML assertion. Which of the following attacks is most directly enabled by this misconfiguration?
Select an answer first - 23
What is a common security risk in federated identity environments?
Select an answer first - 24
What is a SAML assertion?
Select an answer first - 25
How is trust typically established between an identity provider (IdP) and a service provider (SP) in SAML?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCAD” is a trademark of its owner, used for identification only.