nerdexam
Amazon

SCS-C02 · Question #28

A-company uses a third-party identity provider and SAML-based SSO for its AWS accounts. After the third-party identity provider renewed an expired signing certificate, users saw the following…

The correct answer is C. Download the updated SAML metadata file from the identity service provider. Update the file in. https://docs.aws.amazon.com/IAM/latest/UserGuide/troubleshoot_saml.html#troubleshoot_saml_i

Submitted by hans_de· Mar 6, 2026Identity and Access Management

Question

A-company uses a third-party identity provider and SAML-based SSO for its AWS accounts. After the third-party identity provider renewed an expired signing certificate, users saw the following message when trying to log in:

Error: Response Signature Invalid (Service: AWSSecurityTokenService; Status Code: 400; Error Code: InvalidIdentityToken) A security engineer needs to provide a solution that corrects the error and minimizes operational overhead. Which solution meets these requirements?

Options

  • AUpload the third-party signing certificate's new private key to the AWS identity provider entity
  • BSign the identity provider's metadata file with the new public key. Upload the signature to the
  • CDownload the updated SAML metadata file from the identity service provider. Update the file in
  • DConfigure the AWS identity provider entity defined in AWS Identity and Access Management

How the community answered

(42 responses)
  • A
    12% (5)
  • B
    5% (2)
  • C
    81% (34)
  • D
    2% (1)

Explanation

https://docs.aws.amazon.com/IAM/latest/UserGuide/troubleshoot_saml.html#troubleshoot_saml_i

Topics

#SAML#SSO#signing certificate#identity provider

Community Discussion

No community discussion yet for this question.

Full SCS-C02 Practice