Courseiva
Access Controls →mediumMultiple Choice

SSCP Access Controls Practice Question

Which federated identity protocol uses XML-based assertions and provides single sign-on across different security domains?

⚠ Common exam trap

SSCP often tests whether candidates confuse SAML (XML-based, authentication/SSO) with OAuth 2.0 (JSON-based, authorization) and OpenID Connect (JSON/JWT-based, authentication layer on OAuth), so the XML assertion detail is the key discriminator.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SAML

SAML (Security Assertion Markup Language) is an XML-based federated identity protocol that uses assertions to convey authentication and authorization information between identity providers and service providers. It enables single sign-on across different security domains by allowing a user authenticated at one domain to access resources in another without re-authenticating.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Kerberos

    Why it's wrong here

    Kerberos authenticates within a single realm using symmetric-key tickets, not cross-domain XML assertions. It cannot federate identity across separate security domains without explicit cross-realm trusts. Kerberos is the right choice for authenticating users to services inside one Windows or Unix domain, which is not what the question describes.

  • ✗

    OAuth 2.0

    Why it's wrong here

    OAuth 2.0 is an authorisation framework issuing access tokens for delegated API access; it carries no XML assertions and does not itself authenticate users or provide single sign-on. OAuth 2.0 is correct when granting an application limited access to a user's resources without sharing credentials, not for cross-domain SSO.

  • ✗

    OpenID Connect

    Why it's wrong here

    OpenID Connect layers authentication on OAuth 2.0 using JSON Web Tokens, not XML assertions. It delivers SSO for modern web and mobile applications, but the assertion format is JSON. OpenID Connect is the right choice when integrating consumer identity into OAuth-based applications, not when XML-based assertions are mandated.

  • ✓

    SAML

    Why this is correct

    SAML satisfies the cross-domain single sign-on requirement by exchanging XML-based assertions between an identity provider and service provider. Its assertion format carries authentication and attribute statements, enabling federated trust across separate security domains without sharing credentials, which matches the stem's specified XML assertion and SSO constraints precisely.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.