SCS-C02 · Question #147
SCS-C02 Question #147: Real Exam Question with Answer & Explanation
Sign in or unlock SCS-C02 to reveal the answer and full explanation for question #147. The question stem and answer options stay visible for context.
Question
A company uses SAML federation with AWS Identity and Access Management (IAM) to provide internal users with SSO for their AWS accounts. The company's identity provider certificate was rotated as part of its normal lifecycle Shortly after users started receiving the following error when attempting to log in: "Error: Response Signature Invalid (Service: AWSSecurityTokenService; Status Code: 400; Error Code: InvalidIdentityToken)" A security engineer needs to address the immediate issue and ensure that it will not occur again. Which combination of steps should the security engineer take to accomplish this? (Choose two.)
Options
- ADownload a new copy of the SAML metadata file from the identity provider. Create a new IAM
- BDuring the next certificate rotation period and before the current certificate expires, add a new
- CDownload a new copy of the SAML metadata file from the identity provider. Upload the new
- DDuring the next certificate rotation period and before the current certificate expires, add a new
- EDownload a new copy of the SAML metadata file from the identity provider. Create a new IAM
Unlock SCS-C02 to see the answer
You've previewed enough free SCS-C02 questions. Unlock SCS-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.