SSCP Access Controls Practice Question
In a federated identity environment using SAML, what is the role of the Identity Provider (IdP) when a user requests access to a service provider (SP)?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The IdP authenticates the user and issues a SAML assertion to the SP
The IdP authenticates the user and issues a SAML assertion containing identity attributes and authorization claims. The SP trusts this assertion to grant access without re-authenticating the user.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The IdP hosts the application and enforces access control policies
Why it's wrong here
Hosting the application and enforcing access control is the service provider's function; the IdP only authenticates and asserts identity. It is tempting because the IdP does control authentication policy, but in SAML the SP owns the resource and decides what the asserted identity may access.
- ✗
The IdP validates the user's OTP token
Why it's wrong here
OTP validation is an authentication mechanism performed before or during the IdP's own login flow, not the IdP's role in a SAML exchange. It is tempting because the IdP does authenticate users, but its SAML function is to issue a signed assertion to the service provider, which then applies its own authorisation.
- ✗
The IdP generates a Kerberos ticket for the user
Why it's wrong here
Kerberos tickets belong to Kerberos realms, not SAML federation; the IdP issues a signed SAML assertion, not a ticket-granting ticket. It is tempting because both convey authentication claims, but Kerberos would be the mechanism in a Windows domain single sign-on, not a SAML SP-initiated flow.
- ✓
The IdP authenticates the user and issues a SAML assertion to the SP
Why this is correct
In SAML federation the IdP owns authentication, verifying the user's credentials and then issuing a signed assertion describing the authenticated subject. The SP trusts that assertion to grant access, so the IdP never authorises resources itself.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.