CompTIA Cloud Essentials+ (CLO-002)Governance, Risk, Compliance and SecurityMedium

A company wants its employees to authenticate once with their corporate credentials and then seamlessly access multiple independent cloud SaaS applications without re-entering a password for each one. Which IAM capability should the company implement?

  1. AMultifactor authentication
  2. BRole-based access control
  3. CTokenization
  4. DSingle sign-on (federation)
Show answer & explanation

Correct answer: D. Single sign-on (federation)

Single sign-on (SSO), typically enabled through identity federation, allows a user to authenticate once and gain access to multiple independent applications or services without re-entering credentials. Multifactor authentication adds a second verification factor but doesn't eliminate repeated logins across apps, RBAC controls what a user can do rather than how they log in, and tokenization protects sensitive data values rather than managing authentication.

Why the other options are wrong

  • A. MFA strengthens login security but still requires authentication at each application unless paired with SSO.
  • B. RBAC determines authorization levels after login, not the single-login experience itself.
  • C. Tokenization is a data protection technique unrelated to authentication across applications.

Single Sign-On (SSO) / Federation

An IAM capability that allows users to authenticate once and gain access to multiple independent applications or systems without re-authenticating for each one.

  • Often implemented via identity federation protocols like SAML or OAuth/OIDC
  • Improves user experience and reduces password fatigue
  • Relies on a trusted identity provider (IdP) shared across service providers

Memory trick: One badge (SSO) opens many doors across the building without swiping again at each one.

More Governance, Risk, Compliance and Security questions