← All CIAM Flashcard Decks

CIAM Federation and Single Sign-On Flashcards

6 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 CIAM Federation and Single Sign-On flashcards as text
  1. In SAML, what is an 'assertion'?

    Answer: An XML statement conveying information about a subject's identity and attributes

    A SAML assertion is an XML-based statement issued by an Identity Provider that conveys identity, attribute, and authorization decision information about a subject.

  2. What standard is OpenID Connect built on top of?

    Answer: OAuth 2.0

    OpenID Connect is an identity layer built directly on top of OAuth 2.0, adding authentication and identity claims to OAuth's authorization framework.

  3. Which token format is most commonly used in modern OAuth 2.0 and OpenID Connect implementations?

    Answer: JSON Web Token (JWT)

    JSON Web Tokens (JWTs) are widely used as access tokens and ID tokens in OAuth 2.0 and OpenID Connect due to their compact, self-contained structure.

  4. What is 'SP-initiated SSO'?

    Answer: SSO where the user first accesses the Service Provider, which redirects to the IdP

    In SP-initiated SSO, the user first attempts to access a resource at the Service Provider, which then redirects them to the Identity Provider for authentication.

  5. What is the purpose of the audience restriction in a SAML assertion?

    Answer: To specify which Service Provider is authorized to consume the assertion

    The audience restriction in a SAML assertion specifies which Service Provider(s) may use it, preventing a valid assertion from being replayed at an unintended service.

  6. What is 'account linking' in federated identity?

    Answer: Associating a user's local account with an external identity provider account to enable SSO

    Account linking associates a user's local service account with their external Identity Provider account, enabling SSO without requiring identical usernames across systems.