SSCP Access Controls Practice Question
Which federated identity protocol uses XML-based assertions and provides single sign-on across different security domains?
⚠ Common exam trap
SSCP often tests whether candidates confuse SAML (XML-based, authentication/SSO) with OAuth 2.0 (JSON-based, authorization) and OpenID Connect (JSON/JWT-based, authentication layer on OAuth), so the XML assertion detail is the key discriminator.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SAML
SAML (Security Assertion Markup Language) is an XML-based federated identity protocol that uses assertions to convey authentication and authorization information between identity providers and service providers. It enables single sign-on across different security domains by allowing a user authenticated at one domain to access resources in another without re-authenticating.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Kerberos
Why it's wrong here
Kerberos authenticates within a single realm using symmetric-key tickets, not cross-domain XML assertions. It cannot federate identity across separate security domains without explicit cross-realm trusts. Kerberos is the right choice for authenticating users to services inside one Windows or Unix domain, which is not what the question describes.
- ✗
OAuth 2.0
Why it's wrong here
OAuth 2.0 is an authorisation framework issuing access tokens for delegated API access; it carries no XML assertions and does not itself authenticate users or provide single sign-on. OAuth 2.0 is correct when granting an application limited access to a user's resources without sharing credentials, not for cross-domain SSO.
- ✗
OpenID Connect
Why it's wrong here
OpenID Connect layers authentication on OAuth 2.0 using JSON Web Tokens, not XML assertions. It delivers SSO for modern web and mobile applications, but the assertion format is JSON. OpenID Connect is the right choice when integrating consumer identity into OAuth-based applications, not when XML-based assertions are mandated.
- ✓
SAML
Why this is correct
SAML satisfies the cross-domain single sign-on requirement by exchanging XML-based assertions between an identity provider and service provider. Its assertion format carries authentication and attribute statements, enabling federated trust across separate security domains without sharing credentials, which matches the stem's specified XML assertion and SSO constraints precisely.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.