SSCP Access Controls Practice Question
A company is migrating to a cloud-based SaaS application and wants to implement federated identity. Users will authenticate using their existing corporate Active Directory credentials. Which THREE components are essential for a SAML-based federation? (Select THREE.)
⚠ Common exam trap
SSCP often mixes Kerberos components (TGT, KDC) into SAML questions — candidates who see 'ticket' and assume it belongs to federation pick the TGT, forgetting SAML uses assertions, not tickets.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identity Provider (IdP)
In a SAML-based federation, the Identity Provider (IdP) is essential because it is the entity that authenticates users against the corporate Active Directory and issues signed SAML assertions containing authentication and attribute statements (Option A). The Service Provider (SP) is equally essential as the SaaS application that consumes those SAML assertions to grant access, making it the relying party in the federation (Option E). A trust relationship between the IdP and SP is also required, since the SP must trust the IdP's signing certificate and the two parties exchange metadata (entityID, ACS URL, SSO URL, X.509 certificate) to validate assertions and establish the federation (Option B). Option C is incorrect because a Ticket Granting Ticket is a Kerberos construct issued by a Key Distribution Center, not a SAML federation component. Option D is incorrect because an Attribute Authority is a separate SAML role that issues attribute assertions and is not one of the three essential components for basic SAML federation between an IdP and SP.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Identity Provider (IdP)
Why this is correct
The IdP authenticates users against the corporate Active Directory and issues signed SAML assertions to the SaaS relying party, satisfying the requirement that existing credentials be reused. Without it, no trusted authority exists to vouch for user identity, so federation cannot occur.
- ✓
Trust relationship between IdP and SP
Why this is correct
Federation requires a configured trust relationship, typically via exchanged signing certificates and metadata, so the Service Provider accepts assertions the Identity Provider issues. Without this trust, authentication assertions cannot be validated, breaking the stem's SAML federation.
- ✗
Ticket Granting Ticket (TGT)
Why it's wrong here
A TGT is a Kerberos construct issued by a Key Distribution Centre, used for Kerberos-based authentication. SAML federation instead relies on the identity provider issuing signed assertions, the service provider consuming them, and metadata exchange. Kerberos tickets play no part in SAML flows.
- ✗
Attribute Authority (AA)
Why it's wrong here
The Attribute Authority issues attribute assertions about a principal; SAML federation instead requires an identity provider, service provider, and trust metadata. It is tempting because attribute release genuinely matters for authorisation, and an AA would be correct in an X.509 or Shibboleth attribute-query context.
- ✓
Service Provider (SP)
Why this is correct
The SaaS application acts as Service Provider, receiving and validating SAML assertions from the corporate identity source. It is the relying party that grants access, making it essential for the federation described in the stem.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.