CompTIA Security+ (SY0-701)Security OperationsMedium
A company wants employees to authenticate once at their identity provider and then gain access to multiple cloud applications without re-entering credentials. Which technology enables this?
- AFederation using SAML-based single sign-on
- BRole-based access control (RBAC) applied locally on each application
- CMandatory access control (MAC)
- DA local password manager installed on each workstation
Show answer & explanationAnswer & explanation
Correct answer: A. Federation using SAML-based single sign-on
Federation allows an identity provider to authenticate a user once and issue trusted assertions (e.g., via SAML) that multiple service providers accept, enabling single sign-on across separate cloud applications without re-authentication.
Why the other options are wrong
- B. RBAC applied per application still requires separate logins to each system.
- C. MAC is an access control model based on classification labels, not cross-app authentication.
- D. A password manager autofills credentials but does not eliminate separate authentication events.
Federation / SSO
Federation allows identity providers to share authentication assertions with multiple service providers, enabling single sign-on (SSO) across organizational boundaries.
- SAML and OAuth/OIDC are common federation protocols
- One login grants access to multiple trusted apps
- Reduces password fatigue and reuse
- Relies on trust relationship between IdP and SP
Memory trick: Log in once, roam everywhere trusted.