exam questions

Exam CCSP All Questions

View all questions & answers for the CCSP exam

Exam CCSP topic 1 question 104 discussion

Actual exam question from ISC's CCSP
Question #: 104
Topic #: 1
[All CCSP Questions]

What provides the information to an application to make decisions about the authorization level appropriate when granting access?

  • A. User
  • B. Relying party
  • C. Federation
  • D. Identity Provider
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
keresh
Highly Voted 2 years, 2 months ago
Application is the relaying party in the context of federation. The Identity Provider passes the information to the relaying party, which is the application. That's why D is correct
upvoted 5 times
Brittle
1 year ago
Thanks
upvoted 1 times
...
...
MaciekMT
Most Recent 2 days, 3 hours ago
Selected Answer: D
In a federated identity scenario, the Identity Provider (IdP) supplies an assertion or token containing user identity data (often called claims). The application (relying party) then uses this information to make authorization decisions (i.e., what the user is allowed to do).
upvoted 1 times
...
hogancl42004
4 months, 3 weeks ago
My thought is B, "The relying party is any member of the federation that shares resources based on authenticated identities. Relying parties then handle authorization based on their policies. This allows a relying party to determine their level of trust in third-party IdPs and to map permissions on their own rather than relay on the IdP to provide both authentication and authorization. " From the CCSP Official Study Guide, Third Edition pg 181
upvoted 2 times
...
GH1982
1 year, 10 months ago
A relaying party may authorize a user’s request based on authorization attributes fetched from an IdP. Examples of authorization attributes include permissions/privileges assigned to the user or the user’s role. IdP provides the attributes, and answer is D.
upvoted 1 times
...
kepalon
1 year, 11 months ago
Selected Answer: D
it is the right one
upvoted 3 times
...
kepalon
1 year, 11 months ago
Really confusing, as the Authorization is done by the "Relying Party" who is the one that needs to provide the Authrorization. The identity provider, passes the identification+Authentication. I understand your point, and I like the idea of thinking the Application = Relying Party, that way it is easier to point to the Identity Provider as the right answer.
upvoted 2 times
...
sans1241
2 years, 10 months ago
The question talking about which system gives the tokens to be consumed by relying party/application.
upvoted 2 times
...
pooppants
2 years, 11 months ago
I would have said B. The Identity Provider doesnt touch the application. The information comes from the relying party?
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago