🔥 3-day streak
ISACA CDPSE — Certified Data Privacy Solutions Engineer141 / 147
Question 141 of 147

A privacy engineer is reviewing a proposed single sign-on (SSO) architecture where a corporate identity provider (IdP) will federate authentication to a dozen internal applications. Each application currently maintains its own user profile store keyed by email address. Security wants to also pass a rich set of profile attributes (department, manager, phone, physical location) in every SAML assertion to reduce per-app lookups. From a privacy engineering standpoint, what is the MOST appropriate design recommendation?

Reviewed for accuracy · Report an issueNext question