Courseiva
Troubleshooting →mediumMultiple Choice

CV0-004 Troubleshooting Practice Question

A cloud administrator manages a SaaS-based CRM application integrated with an on-premises Active Directory via SAML 2.0. Users report intermittent authentication failures during peak hours (09:00-11:00), with error messages indicating 'SAML assertion validation failed'. The IdP logs show successful authentications, but the SP logs show signature validation errors. The IdP's signing certificate was rotated 30 days ago, and the SP metadata was updated 45 days ago. Which of the following is the MOST likely cause?

⚠ Common exam trap

The trap here is assuming that because the IdP logs show successful authentications, the problem must be on the IdP side, when in fact the SP's stale metadata is the root cause.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The SP's metadata contains an outdated IdP signing certificate.

The IdP rotated its signing certificate 30 days ago, but the SP metadata was last updated 45 days ago, meaning the SP still trusts the old certificate. SAML signature validation requires the SP to use the current IdP signing certificate. The successful IdP authentications and SP signature errors confirm the SP cannot validate assertions signed with the new key. Updating the SP metadata with the new certificate resolves the issue.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The IdP is not including the correct NameID format in the SAML assertion.

    Why it's wrong here

    A NameID format mismatch would typically cause attribute mapping or user identification errors at the SP, not signature validation failures. The error explicitly states 'signature validation errors,' which points to cryptographic trust issues, not assertion content. Moreover, the IdP logs show successful authentications, implying the assertion is generated correctly; the problem lies in the SP's ability to verify the signature.

  • ✗

    The SP's SAML assertion consumer service (ACS) URL is misconfigured.

    Why it's wrong here

    An incorrect ACS URL would prevent the SP from receiving the assertion at all or cause a 404/redirect error, not a signature validation error. Since the SP logs show signature validation errors, it is receiving the assertion but failing to validate the signature. ACS URL misconfiguration would typically manifest as a failure to process the response, not a cryptographic failure.

  • ✓

    The SP's metadata contains an outdated IdP signing certificate.

    Why this is correct

    The SP metadata was updated 45 days ago, but the IdP rotated its signing certificate 30 days ago. SAML signature validation relies on the certificate in the SP's trusted metadata; if it still holds the old certificate, assertions signed with the new key fail validation. This matches the symptom of successful IdP authentication but SP-side signature errors, and the timing discrepancy confirms the metadata is stale.

  • ✗

    The IdP's clock is skewed relative to the SP, causing timestamp validation to fail.

    Why it's wrong here

    Clock skew would trigger 'assertion expired' or 'not yet valid' errors, not signature validation errors. SAML signature validation is independent of timestamps; it verifies the digital signature using the certificate. While clock skew is a common SAML issue, the specific error message here points to a certificate mismatch, and the 30-day gap between certificate rotation and metadata update strongly suggests the SP is using an outdated certificate.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.