Correct Answer: Establishing trust via verified federation metadata exchange, requiring signed and validated assertions, monitoring and proactively renewing certificates, and periodically auditing which SPs are trusted
Explanation: Verified metadata exchange, signed/validated assertions, proactive certificate renewal, and periodic trust audits together provide secure, reliable SSO, unlike hardcoded never-updated settings, accepting unsigned assertions, sharing one certificate across all SPs, never reviewing trusted SPs, or disabling validation to work around configuration issues.
Correct Answer: Establishing trust via verified federation metadata exchange, requiring signed and validated assertions, monitoring and proactively renewing certificates, and periodically auditing which SPs are trusted
Explanation: Verified metadata exchange, signed/validated assertions, proactive certificate renewal, and periodic trust audits together provide secure, reliable SSO, unlike hardcoded never-updated settings, accepting unsigned assertions, sharing one certificate across all SPs, never reviewing trusted SPs, or disabling validation to work around configuration issues.