easyMultiple Select
CISSP Practice Question: Plans to allow employees to access third-party…
An organization plans to allow employees to access third-party SaaS applications using their corporate credentials. Which THREE are necessary components for implementing SAML-based identity federation?
⚠ Common exam trap
Many exam-takers confuse authentication protocols (like RADIUS or password hashing) with federation components, forgetting that SAML is an XML-based assertion framework that requires an IdP, SP, and digital signatures, not network-level or storage mechanisms.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Service Provider (SP)
SAML-based identity federation requires a Service Provider (SP), which is the third-party SaaS application that receives and validates SAML assertions to grant access, so option A is correct. It also requires an Identity Provider (IdP), the corporate system that authenticates employees and issues signed SAML assertions containing identity and attribute claims, making option C correct. XML digital signatures are essential because SAML assertions and responses must be cryptographically signed (typically with XML Signature, using the IdP's private key and validated with its public certificate) to ensure integrity and authenticity, so option E is correct. Bcrypt password hashing (B) is a local credential-storage technique and is not a SAML federation component, since the IdP handles authentication and the SP does not need to hash the user's corporate password. A RADIUS server (D) provides network access authentication via the RADIUS protocol and is unrelated to SAML web-based identity federation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Service Provider (SP)
Why this is correct
The Service Provider (SP) is the entity that hosts the application or resource the user wishes to access. In a SAML exchange, the SP receives and validates the SAML assertion issued by the Identity Provider. Upon successful validation, the SP uses the information within the assertion to establish a local session for the user and grant access to the requested service without requiring a separate login. This role is crucial for enabling single sign-on.
- ✗
Bcrypt password hashing
Why it's wrong here
Bcrypt is a cryptographic hash function specifically designed for securely storing passwords by making brute-force attacks computationally expensive. It incorporates a salt to prevent rainbow table attacks and an adaptive work factor to resist increasing computational power over time. While vital for protecting user credentials, Bcrypt operates at the password storage layer within an Identity Provider and is not a direct architectural component of the SAML protocol itself, which focuses on exchanging authentication and authorization data.
- ✓
Identity Provider (IdP)
Why this is correct
The Identity Provider (IdP) is the authoritative source for user identities and is responsible for authenticating users. Once a user successfully authenticates, the IdP generates a cryptographically signed SAML assertion containing authentication and attribute statements about the user. This assertion is then securely transmitted to the Service Provider, enabling the user to access resources without re-authenticating directly with each application.
- ✗
RADIUS server
Why it's wrong here
A RADIUS (Remote Authentication Dial-In User Service) server is a networking protocol that provides centralized Authentication, Authorization, and Accounting (AAA) management for users connecting to a network service. It is primarily used for network access control, such as VPNs, Wi-Fi, or dial-up connections, and operates at a different layer than web-based single sign-on protocols. RADIUS does not facilitate the exchange of identity assertions between web applications and identity systems in the way SAML does.
- ✓
XML digital signatures
Why this is correct
XML digital signatures are fundamental to the security of SAML assertions, providing cryptographic proof of the assertion's origin and ensuring its integrity. By signing the assertion, the Identity Provider guarantees that the data has not been tampered with in transit and establishes non-repudiation, meaning the IdP cannot later deny having issued the assertion. This mechanism builds trust between the IdP and SP, which is essential for secure single sign-on.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Secure Network Architecture and Components
Key term
SAML
Security Assertion Markup Language (SAML) is an open standard that allows one system to securely tell another system that a user is who they say they are, without sharing the user's password.
Key term
RADIUS
RADIUS is a network protocol that provides centralized authentication, authorization, and accounting management for users who connect and use a network service.
About these practice questions
Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.