Courseiva
mediumMultiple Select

CISSP Practice Question: When implementing a federated identity management…

When implementing a federated identity management system, which TWO components are essential for establishing trust between Identity Provider and Service Provider? (Select two.)

⚠ Common exam trap

Test-takers frequently confuse operational components like user synchronization or session management with the foundational trust-establishing mechanisms, forgetting that federated trust relies on cryptographic verification through metadata and certificates, not shared secrets or directory replication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Metadata exchange

Metadata exchange (A) is essential because the IdP and SP must exchange XML metadata documents describing their entity IDs, endpoints (SSO, SLO), supported bindings, and signing/encryption certificates before any assertion can be trusted. Public key certificates (E) are essential because the SP validates the IdP's digital signature on SAML assertions (or the IdP validates tokens) using the IdP's public key, establishing cryptographic trust; the private key never leaves the IdP. Together, metadata exchange distributes the certificates and endpoint configuration that make signature verification and secure message routing possible. User directory synchronization (B) is not required — federated identity relies on just-in-time provisioning or attribute statements rather than replicating directories. Single logout (C) is a session-management convenience, not a trust-establishment requirement. Shared secret (D) applies to symmetric schemes like WS-Security or OAuth client secrets, but SAML federation trust is built on asymmetric keys and metadata, not a shared secret.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Metadata exchange

    Why this is correct

    Metadata exchange is crucial for establishing trust in a federated identity management system because it provides a standardized way for identity providers (IdPs) and service providers (SPs) to share configuration information. This metadata, typically an XML document, includes essential details such as entity IDs, endpoint URLs for various services (e.g., SSO, SLO), and critically, the public key certificates used for signing and encryption. This exchange allows entities to automatically configure their trust relationships, validate digital signatures on assertions, and encrypt communications, forming the foundational basis for secure authentication.

  • ✗

    User directory synchronization

    Why it's wrong here

    User directory synchronization involves replicating user accounts and attributes between different directories, often for centralized user management or provisioning across an organization. While it can be a component of a broader identity management strategy, it does not directly establish the cryptographic trust relationship or secure communication channels between feder federated identity providers and service providers. The synchronization of user data is distinct from the mechanisms required to securely verify the authenticity and integrity of identity assertions exchanged between federated entities.

  • ✗

    Single logout

    Why it's wrong here

    Single Logout (SLO) is a convenience feature in federated identity systems that allows a user to terminate all active sessions across multiple service providers with a single action. While SLO enhances user experience and improves security by preventing orphaned sessions, it is an optional component of federated identity protocols like SAML and is not a prerequisite for establishing the initial cryptographic trust or enabling secure authentication between federated entities. The core trust relationship can exist and function without SLO being implemented.

  • ✗

    Shared secret

    Why it's wrong here

    Modern federated identity management systems, particularly those utilizing protocols like SAML or OpenID Connect, primarily rely on asymmetric cryptography and public key certificates for establishing trust and securing communications. Shared secrets, while used in some authentication mechanisms (e.g., OAuth client secrets for application registration), are generally not the primary method for establishing the foundational, cryptographically verifiable trust between federated identity providers and service providers for assertion signing and encryption. Certificates provide non-repudiation and key management benefits that shared secrets lack in this context.

  • ✓

    Public key certificates

    Why this is correct

    Public key certificates are fundamental to establishing cryptographic trust in federated identity systems. They bind a public key to a specific identity (e.g., an Identity Provider or Service Provider) and are used for digitally signing SAML assertions or OpenID Connect tokens, enabling the receiving entity to verify the authenticity and integrity of the claims. Certificates also facilitate the establishment of secure, encrypted communication channels, ensuring the confidentiality of sensitive identity information exchanged between federated partners, thereby preventing tampering and eavesdropping.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.