shieldCISSP Practice Domain 5 — Identity and Access Management (IAM) Q84 of 120

Which is FALSE about SAML?

A CISSP practice question covering Domain 5: Identity and Access Management (IAM). Try answering before reading the explanation below.

Show options & answer
A
Uses XML-based assertions
B
Operates over HTTP redirects/POSTs
C
Provides cross-organization SSO
D
Replaces Kerberos in AD environments
✓ Correct answer
Why "Replaces Kerberos in AD environments" is the right answer

SAML enables web SSO across organizations — typically delegating identity to an external IdP. It does not replace Kerberos for AD service-to-service auth on a LAN. The other three statements are accurate.

Study videos for this topic

Want to go deeper on Domain 5? Watch the full breakdown — every video is free, no account, no upsell.

Take the full CISSP practice test
120 questions, instant explanations, study-video links on every miss. No account.
Start full test →