CompTIA Server+ (SK0-005)Security and Disaster RecoveryHard
A large enterprise is implementing a new identity and access management (IAM) solution. They require a centralized directory service that can manage user accounts, groups, and permissions across multiple operating systems and applications. The solution must support a hierarchical structure and be widely compatible with various vendor products. Which protocol is best suited for this requirement?
- ALDAP
- BKerberos
- CTACACS+
- DRADIUS
Show answer & explanationAnswer & explanation
Correct answer: A. LDAP
LDAP (Lightweight Directory Access Protocol) is the industry standard for accessing and maintaining distributed directory information services. It supports a hierarchical structure and is widely used for centralized management of user identities, groups, and authentication across diverse systems.
Why the other options are wrong
- B. Kerberos is primarily an authentication protocol, not a directory service for managing user accounts and groups.
- C. TACACS+ (Terminal Access Controller Access-Control System Plus) is similar to RADIUS, focusing on AAA for network devices, not a broad directory service.
- D. RADIUS (Remote Authentication Dial-In User Service) is used for centralized authentication, authorization, and accounting (AAA) for network access, not a general-purpose directory service.
LDAP
Lightweight Directory Access Protocol; an open, vendor-neutral, industry standard application protocol for accessing and maintaining distributed directory information services.
- Hierarchical structure.
- Centralized identity management.
- Widely compatible (e.g., Active Directory, OpenLDAP).
Memory trick: LDAP is like a 'library' for users and their info.