nerdexam
Amazon

SCS-C02 · Question #298

A company uses SAML federation with AWS Identity and Access Management (IAM) to provide internal users with SSO for their AWS accounts. The company's identity provider certificate was rotated as…

The correct answer is B. During the next certificate rotation period and before the current certificate expires, add a new C. Download a new copy of the SAML metadata file from the identity provider. B: https://docs.aws.amazon.com/singlesignon/latest/userguide/rotatesamlcert.html https://docs.aws.amazon.com/IAM/latest/UserGuide/troubleshoot_saml.html#troubleshoot_saml_i

Submitted by eva_at· Mar 6, 2026Identity and Access Management

Question

A company uses SAML federation with AWS Identity and Access Management (IAM) to provide internal users with SSO for their AWS accounts. The company's identity provider certificate was rotated as part of its normal lifecycle. Shortly after, users started receiving the following error when attempting to log in:

"Error: Response Signature Invalid (Service: AWSSecurityTokenService; Status Code: 400; Error Code: InvalidIdentityToken)" A security engineer needs to address the immediate issue and ensure that it will not occur again. Which combination of steps should the security engineer take to accomplish this? (Choose two.)

Options

  • ADownload a new copy of the SAML metadata file from the identity provider
  • BDuring the next certificate rotation period and before the current certificate expires, add a new
  • CDownload a new copy of the SAML metadata file from the identity provider
  • DDuring the next certificate rotation period and before the current certificate expires, add a new
  • EDownload a new copy of the SAML metadata file from the identity provider

How the community answered

(27 responses)
  • A
    4% (1)
  • B
    81% (22)
  • D
    11% (3)
  • E
    4% (1)

Explanation

B: https://docs.aws.amazon.com/singlesignon/latest/userguide/rotatesamlcert.html https://docs.aws.amazon.com/IAM/latest/UserGuide/troubleshoot_saml.html#troubleshoot_saml_i

Topics

#SAML federation#certificate rotation#IAM identity provider#SSO

Community Discussion

No community discussion yet for this question.

Full SCS-C02 Practice