shieldCISSP Practice Domain 5 — Identity and Access Management (IAM) Q28 of 120

Which attack against single sign-on attempts to forge or replay an assertion that grants the attacker someone else's session?

A CISSP practice question covering Domain 5: Identity and Access Management (IAM). Try answering before reading the explanation below.

Show options & answer
A
Session fixation
B
Token impersonation / SAML assertion forgery
✓ Correct answer
C
Pass-the-cookie
D
Phishing
Why "Token impersonation / SAML assertion forgery" is the right answer

Token-impersonation attacks (e.g., Golden SAML, forged JWT) create or replay a valid-looking assertion to bypass authentication. Strong signing, short token lifetimes, and audience/issuer validation are the defenses. Session fixation forces a known session ID; pass-the-cookie steals a live cookie; phishing is a delivery method.

Study videos for this topic

Want to go deeper on Domain 5? Watch the full breakdown — every video is free, no account, no upsell.

Take the full CISSP practice test
120 questions, instant explanations, study-video links on every miss. No account.
Start full test →