Courseiva

CCSP Cloud Concepts, Architecture, and Design Practice Question

A cloud architect is designing a federated identity solution so that employees of a partner company can access a shared SaaS application without creating separate local accounts. The architect must select mechanisms that enable secure cross-domain authentication and attribute exchange. (Choose two.)

⚠ Common exam trap

The trap here is selecting a transport security mechanism such as IPsec, which protects packets but never authenticates users across domains.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

OpenID Connect (OIDC)

Federated identity requires protocols that carry authentication assertions and user attributes across security domains. SAML 2.0 and OpenID Connect both do this, allowing partner employees to authenticate with their home identity provider and access the shared SaaS application without local accounts. IPsec, DLP endpoint agents, and DHCP snooping operate at network or data layers and cannot federate identities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    OpenID Connect (OIDC)

    Why this is correct

    OIDC builds on OAuth 2.0 to provide federated authentication and delivers identity attributes through the ID token and UserInfo endpoint. It enables partner users to authenticate through their home identity provider and access the SaaS application without local accounts, satisfying the cross-domain authentication and attribute exchange requirement.

  • ✗

    Data Loss Prevention (DLP) endpoint agent

    Why it's wrong here

    A DLP endpoint agent inspects and blocks sensitive data movement on managed devices but has no role in authenticating users or exchanging identity attributes across domains. It addresses data exfiltration risk rather than federation, so it does not fulfill the architect's requirement for cross-domain authentication.

  • ✗

    Internet Protocol Security (IPsec) transport mode

    Why it's wrong here

    IPsec transport mode encrypts and authenticates individual IP packets between hosts but does not federate identities or exchange user attributes. It secures network traffic, not authentication assertions, so it cannot enable partner employees to access the SaaS application through cross-domain identity federation.

  • ✗

    Dynamic Host Configuration Protocol (DHCP) snooping

    Why it's wrong here

    DHCP snooping is a Layer 2 switch feature that filters untrusted DHCP messages to prevent rogue servers and spoofing. It operates on local network traffic and has no capability to federate identities or transmit authentication assertions, so it is irrelevant to enabling partner access to a SaaS application.

  • ✓

    Security Assertion Markup Language (SAML) 2.0

    Why this is correct

    SAML 2.0 is designed for cross-domain single sign-on and carries authentication and attribute assertions between an identity provider and a service provider. It directly supports federated access for partner employees without local accounts, making it a correct mechanism for the stated requirement of cross-domain authentication and attribute exchange.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.