mediumMultiple Select
CISSP Practice Question: When implementing a federated identity management…
When implementing a federated identity management system, which TWO components are essential for establishing trust between Identity Provider and Service Provider? (Select two.)
⚠ Common exam trap
Test-takers frequently confuse operational components like user synchronization or session management with the foundational trust-establishing mechanisms, forgetting that federated trust relies on cryptographic verification through metadata and certificates, not shared secrets or directory replication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Metadata exchange
Metadata exchange (A) is essential because the IdP and SP must exchange XML metadata documents describing their entity IDs, endpoints (SSO, SLO), supported bindings, and signing/encryption certificates before any assertion can be trusted. Public key certificates (E) are essential because the SP validates the IdP's digital signature on SAML assertions (or the IdP validates tokens) using the IdP's public key, establishing cryptographic trust; the private key never leaves the IdP. Together, metadata exchange distributes the certificates and endpoint configuration that make signature verification and secure message routing possible. User directory synchronization (B) is not required — federated identity relies on just-in-time provisioning or attribute statements rather than replicating directories. Single logout (C) is a session-management convenience, not a trust-establishment requirement. Shared secret (D) applies to symmetric schemes like WS-Security or OAuth client secrets, but SAML federation trust is built on asymmetric keys and metadata, not a shared secret.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Metadata exchange
Why this is correct
Metadata exchange is crucial for establishing trust in a federated identity management system because it provides a standardized way for identity providers (IdPs) and service providers (SPs) to share configuration information. This metadata, typically an XML document, includes essential details such as entity IDs, endpoint URLs for various services (e.g., SSO, SLO), and critically, the public key certificates used for signing and encryption. This exchange allows entities to automatically configure their trust relationships, validate digital signatures on assertions, and encrypt communications, forming the foundational basis for secure authentication.
- ✗
User directory synchronization
Why it's wrong here
User directory synchronization involves replicating user accounts and attributes between different directories, often for centralized user management or provisioning across an organization. While it can be a component of a broader identity management strategy, it does not directly establish the cryptographic trust relationship or secure communication channels between feder federated identity providers and service providers. The synchronization of user data is distinct from the mechanisms required to securely verify the authenticity and integrity of identity assertions exchanged between federated entities.
- ✗
Single logout
Why it's wrong here
Single Logout (SLO) is a convenience feature in federated identity systems that allows a user to terminate all active sessions across multiple service providers with a single action. While SLO enhances user experience and improves security by preventing orphaned sessions, it is an optional component of federated identity protocols like SAML and is not a prerequisite for establishing the initial cryptographic trust or enabling secure authentication between federated entities. The core trust relationship can exist and function without SLO being implemented.
- ✗
Shared secret
Why it's wrong here
Modern federated identity management systems, particularly those utilizing protocols like SAML or OpenID Connect, primarily rely on asymmetric cryptography and public key certificates for establishing trust and securing communications. Shared secrets, while used in some authentication mechanisms (e.g., OAuth client secrets for application registration), are generally not the primary method for establishing the foundational, cryptographically verifiable trust between federated identity providers and service providers for assertion signing and encryption. Certificates provide non-repudiation and key management benefits that shared secrets lack in this context.
- ✓
Public key certificates
Why this is correct
Public key certificates are fundamental to establishing cryptographic trust in federated identity systems. They bind a public key to a specific identity (e.g., an Identity Provider or Service Provider) and are used for digitally signing SAML assertions or OpenID Connect tokens, enabling the receiving entity to verify the authenticity and integrity of the claims. Certificates also facilitate the establishment of secure, encrypted communication channels, ensuring the confidentiality of sensitive identity information exchanged between federated partners, thereby preventing tampering and eavesdropping.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
Learn chapter
Identity and Access Management (IAM)
Key term
IDS
An IDS is a security system that monitors network or system traffic for suspicious activity and alerts administrators to potential threats, but does not actively block them.
Key term
SAML
Security Assertion Markup Language (SAML) is an open standard that allows one system to securely tell another system that a user is who they say they are, without sharing the user's password.
About these practice questions
One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.