Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Security Architecture and Design

Domain 1Objective 3

Federated Access and SSO GCAD Practice Questions (Page 9)

Part of the Identity and Access Management domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 3–5 from this objective — we provide 60 practice questions to prepare you well beyond it. (estimate)

60questions here
12free pages
15concepts

Questions 41–45

  1. 41foundation · easy

    What is the benefit of using federated identity to access a cloud provider like Azure Active Directory?

    Select an answer first
  2. 42foundation · easy

    What is the artifact binding in SAML?

    Select an answer first
  3. 43application · medium

    A company is evaluating protocols for a new customer-facing web application that needs to support social login (e.g., Google, Facebook) and also allow users to access a REST API. The development team wants a single protocol that can handle both authentication and API authorization. Which protocol should the architect recommend?

    Select an answer first
  4. 44application · medium

    A company is building a mobile app that will let users sign in with their existing corporate accounts. The app needs to call a REST API on behalf of the user. The security team wants to avoid exposing the user's password to the app and wants the API to validate the user's identity without making a separate call back to the corporate identity provider on every request. Which approach should the architect recommend?

    Select an answer first
  5. 45expert · hard

    A security architect is reviewing a federated SSO deployment where users authenticate at an on-premises IdP and then access a SaaS application. The SaaS application accepts SAML assertions but does not enforce a maximum session lifetime. The IdP issues assertions with a SessionNotOnOrAfter condition of 8 hours. An attacker steals a valid assertion from a user's browser history. Which control would most directly limit the attacker's ability to reuse that assertion?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCAD” is a trademark of its owner, used for identification only.