SAML Parameters for Mixed Cloud Identity Management
What are two parameters that can be leveraged by SAML in mixed private/public cloud environments by using identity and asset management? (Choose two.)
Community Votes
57% of anonymous learners picked answer BD. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests knowledge of specific SAML components; the common trap is confusing infrastructure-level directory management with protocol-level token and federation parameters.
This question tests the ability to identify key SAML parameters used in mixed cloud environments. It establishes that policy-based tokens and identity federations are the correct mechanisms for managing access and trust.
Many candidates choose 'unified directories' because it sounds like a central management solution, but it is an infrastructure component rather than a SAML parameter leveraged via identity and asset management protocols.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Policy-based tokens (B) allow SAML assertions to carry specific entitlements and policies, enabling granular access control across hybrid cloud boundaries. Identity federations (D) establish the trust relationships between identity providers (IdP) and service providers (SP), which is the foundational mechanism for SAML to work in mixed environments. Together, they leverage identity and asset management to ensure secure, consistent access.Why the Other Options Are Wrong
Unified directories (A) refer to backend data stores (like LDAP/Active Directory) that might be sources of truth, but they are not SAML parameters themselves. Link federations (C) is not a standard term in SAML or IAM contexts; SAML uses identity or service federations. Multifactor hard tokens (E) are authentication factors (hardware devices), not parameters or mechanisms defined within the SAML protocol structure for managing assets or identities.Community Comment Notes
Community comments show a split between BD and AD. Some learners argue for unified directories based on general IAM concepts, but fail to distinguish between the directory service and the SAML protocol parameters. Others correctly identify that SAML relies on federation and token structures rather than just directory synchronization.Official Reference
Exam Strategy
When asked about 'parameters' or 'mechanisms' of a specific protocol (like SAML, OAuth, or Kerberos), focus on the elements defined by that protocol's specification, not the underlying infrastructure components. Distinguish between where identity is stored (directory) and how it is asserted/transferred (federation/tokens).
Frequently Asked Questions
Why is unified directory not a SAML parameter?
A unified directory is a backend storage system (like LDAP) that holds user data. SAML is a protocol that exchanges assertions about users. The directory feeds the IdP, but is not itself a SAML parameter.
What is the difference between identity and link federation?
Identity federation establishes trust between identity providers. 'Link federation' is not a standard SAML/IAM term; it likely refers to URL linking, which is irrelevant to SAML parameterization.