Courseiva
Access Controls →hardMultiple Choice

SSCP Access Controls Practice Question

In a federated identity environment using SAML, what is the role of the Identity Provider (IdP) when a user requests access to a service provider (SP)?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The IdP authenticates the user and issues a SAML assertion to the SP

The IdP authenticates the user and issues a SAML assertion containing identity attributes and authorization claims. The SP trusts this assertion to grant access without re-authenticating the user.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The IdP hosts the application and enforces access control policies

    Why it's wrong here

    Hosting the application and enforcing access control is the service provider's function; the IdP only authenticates and asserts identity. It is tempting because the IdP does control authentication policy, but in SAML the SP owns the resource and decides what the asserted identity may access.

  • ✗

    The IdP validates the user's OTP token

    Why it's wrong here

    OTP validation is an authentication mechanism performed before or during the IdP's own login flow, not the IdP's role in a SAML exchange. It is tempting because the IdP does authenticate users, but its SAML function is to issue a signed assertion to the service provider, which then applies its own authorisation.

  • ✗

    The IdP generates a Kerberos ticket for the user

    Why it's wrong here

    Kerberos tickets belong to Kerberos realms, not SAML federation; the IdP issues a signed SAML assertion, not a ticket-granting ticket. It is tempting because both convey authentication claims, but Kerberos would be the mechanism in a Windows domain single sign-on, not a SAML SP-initiated flow.

  • ✓

    The IdP authenticates the user and issues a SAML assertion to the SP

    Why this is correct

    In SAML federation the IdP owns authentication, verifying the user's credentials and then issuing a signed assertion describing the authenticated subject. The SP trusts that assertion to grant access, so the IdP never authorises resources itself.

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.