nerdexam
Cisco

500-444 · Question #32

Where should a trust relationship be established by downloading and exchanging a metadata file when configuring the Cisco IdS using PCCE Web Administration Manager (S.P.O.G)?

The correct answer is A. IdS to IdP. When configuring the Cisco IdS through PCCE Web Administration Manager (S.P.O.G), you are working within the IdS itself - so the trust you establish from that interface is the IdS learning to trust the IdP. This is done by downloading the IdP's metadata file and importing it…

Advanced Features and Integration Implementation

Question

Where should a trust relationship be established by downloading and exchanging a metadata file when configuring the Cisco IdS using PCCE Web Administration Manager (S.P.O.G)?

Options

  • AIdS to IdP
  • BIdS to IdP and IdP to IdS
  • CIdP to IdS
  • DIdS to IdP and IdP to Active Directory (AD)

How the community answered

(30 responses)
  • A
    87% (26)
  • C
    3% (1)
  • D
    10% (3)

Explanation

When configuring the Cisco IdS through PCCE Web Administration Manager (S.P.O.G), you are working within the IdS itself - so the trust you establish from that interface is the IdS learning to trust the IdP. This is done by downloading the IdP's metadata file and importing it into the IdS, creating a one-directional trust: IdS → IdP. Option B is tempting but wrong - while mutual trust IS required for SSO to function end-to-end, the IdP-to-IdS trust is configured on the IdP side (e.g., in ADFS or another identity provider), not through PCCE Web Admin. Option C reverses the direction entirely - you cannot configure the IdP's trust relationship from within the PCCE/IdS interface. Option D is incorrect because Active Directory is an authentication backend for the IdP, not a direct party in the SAML metadata exchange. Memory tip: Think of S.P.O.G as your "house controls" - you can only configure what your house (IdS) trusts from inside it; to make the IdP trust you back, you have to go to the IdP's house separately.

Topics

#SAML Metadata Exchange#IdS Configuration#Trust Relationships#PCCE Authentication

Community Discussion

No community discussion yet for this question.

Full 500-444 Practice