SAML Parameters for Mixed Cloud Identity Management

Answer Correct answer: B, D — Policy-based tokens and identity federations are the two parameters leveraged by SAML for identity and asset management in mixed cloud environments.

What are two parameters that can be leveraged by SAML in mixed private/public cloud environments by using identity and asset management? (Choose two.)

  1. unified directories
  2. policy-based tokens Correct Answer
  3. link federations
  4. identity federations Correct Answer
  5. multifactor hard tokens

Community Votes

BD
57%
AD
43%

57% of anonymous learners picked answer BD. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests knowledge of specific SAML components; the common trap is confusing infrastructure-level directory management with protocol-level token and federation parameters.

This question tests the ability to identify key SAML parameters used in mixed cloud environments. It establishes that policy-based tokens and identity federations are the correct mechanisms for managing access and trust.

Many candidates choose 'unified directories' because it sounds like a central management solution, but it is an infrastructure component rather than a SAML parameter leveraged via identity and asset management protocols.

Community Discussion (3 comments)

Redrum702 👍 1 Selected: AD
Answer is AD: A. Unified directories: This allows for a consistent and centralized directory service that can manage user identities across both private and public cloud environments, facilitating seamless authentication and access control. D. Identity federations: This enables the establishment of trust relationships between different identity providers, allowing users to authenticate across multiple systems (private and public clouds) without needing separate credentials for each.
Seawanderer 👍 4 Selected: BD
B. policy-based tokens D. identity federations 1. Policy-Based Tokens: SAML can use policy-based tokens to enforce access control policies across different cloud environments. These tokens carry specific attributes and policies that dictate what resources a user can access and under what conditions, thereby ensuring consistent access control in mixed cloud environments. 2. Identity Federations: SAML supports identity federations, which allow different organizations or cloud environments to trust and accept each other’s user credentials. This is crucial in a mixed cloud environment, enabling seamless and secure access to resources across private and public clouds by federating identities.
bdp123 👍 2 Selected: AD
seems correct based on the following https://jumpcloud.com/blog/identity-federation-services

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Policy-based tokens (B) allow SAML assertions to carry specific entitlements and policies, enabling granular access control across hybrid cloud boundaries. Identity federations (D) establish the trust relationships between identity providers (IdP) and service providers (SP), which is the foundational mechanism for SAML to work in mixed environments. Together, they leverage identity and asset management to ensure secure, consistent access.

Why the Other Options Are Wrong

Unified directories (A) refer to backend data stores (like LDAP/Active Directory) that might be sources of truth, but they are not SAML parameters themselves. Link federations (C) is not a standard term in SAML or IAM contexts; SAML uses identity or service federations. Multifactor hard tokens (E) are authentication factors (hardware devices), not parameters or mechanisms defined within the SAML protocol structure for managing assets or identities.

Community Comment Notes

Community comments show a split between BD and AD. Some learners argue for unified directories based on general IAM concepts, but fail to distinguish between the directory service and the SAML protocol parameters. Others correctly identify that SAML relies on federation and token structures rather than just directory synchronization.

Official Reference

Exam Strategy

When asked about 'parameters' or 'mechanisms' of a specific protocol (like SAML, OAuth, or Kerberos), focus on the elements defined by that protocol's specification, not the underlying infrastructure components. Distinguish between where identity is stored (directory) and how it is asserted/transferred (federation/tokens).

Frequently Asked Questions

Why is unified directory not a SAML parameter?

A unified directory is a backend storage system (like LDAP) that holds user data. SAML is a protocol that exchanges assertions about users. The directory feeds the IdP, but is not itself a SAML parameter.

What is the difference between identity and link federation?

Identity federation establishes trust between identity providers. 'Link federation' is not a standard SAML/IAM term; it likely refers to URL linking, which is irrelevant to SAML parameterization.

Related Analysis

← Back to 400-007 Study Guide