ExamGecko
Home Home / ISC / CISSP
Question list
Search
Search

Question 1228 - CISSP discussion

Report
Export

A cloud service accepts Security Assertion Markup Language (SAML) assertions from users to on and security However, an attacker was able to spoof a registered account on the network and query the SAML provider.

What is the MOST common attack leverage against this flaw?

A.
Attacker forges requests to authenticate as a different user.
Answers
A.
Attacker forges requests to authenticate as a different user.
B.
Attacker leverages SAML assertion to register an account on the security domain.
Answers
B.
Attacker leverages SAML assertion to register an account on the security domain.
C.
Attacker conducts denial-of-service (DoS) against the security domain by authenticating as the same user repeatedly.
Answers
C.
Attacker conducts denial-of-service (DoS) against the security domain by authenticating as the same user repeatedly.
D.
Attacker exchanges authentication and authorization data between security domains.
Answers
D.
Attacker exchanges authentication and authorization data between security domains.
Suggested answer: A
asked 18/09/2024
Gerald Saraci
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first