CompTIA Security+ (SY0-701)Security OperationsMedium

A company wants employees to authenticate once at their identity provider and then gain access to multiple cloud applications without re-entering credentials. Which technology enables this?

  1. AFederation using SAML-based single sign-on
  2. BRole-based access control (RBAC) applied locally on each application
  3. CMandatory access control (MAC)
  4. DA local password manager installed on each workstation
Show answer & explanation

Correct answer: A. Federation using SAML-based single sign-on

Federation allows an identity provider to authenticate a user once and issue trusted assertions (e.g., via SAML) that multiple service providers accept, enabling single sign-on across separate cloud applications without re-authentication.

Why the other options are wrong

  • B. RBAC applied per application still requires separate logins to each system.
  • C. MAC is an access control model based on classification labels, not cross-app authentication.
  • D. A password manager autofills credentials but does not eliminate separate authentication events.

Federation / SSO

Federation allows identity providers to share authentication assertions with multiple service providers, enabling single sign-on (SSO) across organizational boundaries.

  • SAML and OAuth/OIDC are common federation protocols
  • One login grants access to multiple trusted apps
  • Reduces password fatigue and reuse
  • Relies on trust relationship between IdP and SP

Memory trick: Log in once, roam everywhere trusted.

More Security Operations questions