
GIAC Cloud Security Architecture and Design
Domain 1Objective 3
Federated Access and SSO GCAD Practice Questions (Page 6)
Part of the Identity and Access Management domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 3–5 from this objective — we provide 60 practice questions to prepare you well beyond it. (estimate)
60questions here
12free pages
15concepts
Questions 26–30
- 26
A security analyst is investigating a potential SAML assertion replay attack. The analyst notices that the SP does not track previously used assertion IDs. Which of the following is the most effective control to prevent replay attacks?
Select an answer first - 27
In a federated identity model, what is the role of the identity provider (IdP)?
Select an answer first - 28
A security architect is reviewing a SAML federation setup. The IdP and SP exchange metadata over an unencrypted channel during initial configuration. An attacker intercepts the metadata and modifies the SP's assertion consumer service (ACS) URL to point to an attacker-controlled endpoint. What is the primary risk from this tampering?
Select an answer first - 29
An organization has deployed SAML-based SSO for multiple SaaS applications. Users report that when they log out of one application, they remain logged in to the others. The security team wants to ensure that logging out of any one application terminates all federated sessions. Which of the following is the most effective solution?
Select an answer first - 30
Which component is central to WS-Federation's architecture?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCAD” is a trademark of its owner, used for identification only.