CISSP Identity and Access Management Practice Question
A healthcare organization uses a federated identity provider (IdP) to authenticate clinicians into a third-party electronic health record (EHR) application acting as a SAML 2.0 Service Provider (SP). The security team wants to reduce the risk that a stolen IdP session cookie could be replayed against the EHR. Which SAML 2.0 control should the team implement to bind the assertion to the authenticated browser session and limit replay?
⚠ Common exam trap
The trap here is assuming that shortening assertion lifetime or enabling Single Logout prevents cookie replay, when neither binds the assertion to the requester's session.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require the IdP to include a Holder-of-Key (HoK) subject confirmation in the assertion and have the SP verify possession of the corresponding key.
Binding a SAML assertion to a key the requester must prove possession of prevents an attacker who only has a stolen cookie from being accepted by the Service Provider, because the attacker cannot demonstrate possession of the associated private key. Short-lived assertions, Single Logout, and the ECP profile change timing or transport but leave the assertion bearer-based and replayable within its validity window.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable SAML 2.0 Single Logout (SLO) between the IdP and the EHR Service Provider.
Why it's wrong here
Single Logout terminates sessions across the federation when a user logs out, which limits lingering sessions but does nothing to prevent an attacker from replaying a stolen session cookie while the legitimate session is still active. It is a session-termination control, not a session-binding or anti-replay control.
- ✓
Require the IdP to include a Holder-of-Key (HoK) subject confirmation in the assertion and have the SP verify possession of the corresponding key.
Why this is correct
Holder-of-Key subject confirmation binds the assertion to a key the requester must prove possession of, so a stolen session cookie alone cannot satisfy the SP. This directly addresses replay of a captured assertion or cookie, which is exactly the risk the security team wants to reduce for clinician access to the EHR.
- ✗
Configure the IdP to issue short-lived assertions and require the SP to validate the NotOnOrAfter condition against its own clock.
Why it's wrong here
Short-lived assertions and clock validation reduce the window in which a captured assertion is usable, but they do not bind the assertion to the specific browser session. A stolen cookie replayed within the validity window would still be accepted, so this does not address the session-binding requirement described in the scenario.
- ✗
Use SAML 2.0 Enhanced Client or Proxy (ECP) profile so the EHR can request authentication directly from the IdP.
Why it's wrong here
The ECP profile is designed for non-browser clients such as thick applications that cannot follow browser redirects. It changes how authentication requests are conveyed, not how assertions are bound to a browser session, so it does not mitigate cookie replay against a browser-based EHR login.
Go deeper
Related to this question
Learn chapter
Identity and Access Management (IAM)
Key term
SAML
Security Assertion Markup Language (SAML) is an open standard that allows one system to securely tell another system that a user is who they say they are, without sharing the user's password.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.