> but blocking only one would be impossible without ....

This is a great interview question for a fairly high-level IAM position .. have them whiteboard that.

"Consider the case of an existing SAML assertion issued by a consortium such as InCommon. How might one forcefully revoke such an assertion"

  1.  How quickly would (whatever they came up with) work?
  2.  How well would it scale?
