Courseiva

CISSP Identity and Access Management Practice Question

An organization implements Single Sign-On (SSO) using SAML 2.0. A user attempts to access a cloud application (Service Provider) but is not authenticated. The Service Provider redirects the user to the Identity Provider (IdP) for authentication. Which type of SAML flow is this?

⚠ Common exam trap

CISSP often tests the distinction between SP-initiated and IdP-initiated SSO by describing the starting point of the user's access attempt; candidates frequently confuse the direction of the initial request and incorrectly choose IdP-initiated when the user actually starts at the application.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SP-initiated SSO

In SAML 2.0, SP-initiated SSO occurs when the user first attempts to access a protected resource at the Service Provider (SP). The SP, finding no valid session, generates a SAML AuthnRequest and redirects the user to the Identity Provider (IdP) for authentication. This matches the scenario exactly: the user goes to the cloud application (SP) first, is redirected to the IdP, and then authentication proceeds.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AuthN-initiated SSO

    Why it's wrong here

    "AuthN-initiated SSO" is not a standard or recognized term within the Security Assertion Markup Language (SAML) specification for describing single sign-on (SSO) initiation flows. While authentication (AuthN) is a fundamental component of any SSO process, the initiation of the SAML exchange is defined by whether the Service Provider (SP) or the Identity Provider (IdP) first generates and sends a SAML message to the user agent, not by the act of authentication itself. This term incorrectly conflates the authentication event with the architectural flow initiation.

  • ✓

    SP-initiated SSO

    Why this is correct

    SP-initiated SSO occurs when a user attempts to access a protected resource directly from a Service Provider (SP). The SP detects the unauthenticated request, generates a SAML authentication request, and redirects the user's browser to the Identity Provider (IdP) along with this request. After the IdP authenticates the user, it creates a SAML assertion and redirects the user's browser back to the SP, allowing the user to access the requested resource without re-authenticating directly to the SP.

  • ✗

    Assertion-initiated SSO

    Why it's wrong here

    "Assertion-initiated SSO" is not a standard or technically accurate term in the context of SAML 2.0. A SAML assertion is the XML document issued by the Identity Provider (IdP) that contains authentication, authorization, and attribute statements about a user. It is the *payload* or *result* of an authentication process, not the entity that initiates an SSO flow. The initiation of an SSO flow is always driven by either a Service Provider's request or an Identity Provider's proactive issuance.

  • ✗

    IdP-initiated SSO

    Why it's wrong here

    IdP-initiated SSO describes a flow where the user begins their journey at the Identity Provider (IdP) portal, authenticates there, and then selects a specific Service Provider (SP) application from a list or dashboard. The IdP then generates a SAML assertion containing the user's authentication details and redirects the user's browser directly to the SP with this assertion. This method bypasses the need for the SP to send an initial authentication request, as the IdP proactively pushes the authentication context to the SP.

About these practice questions

Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.