CompTIA Cloud+ (CV0-004)SecurityEasy
A cloud administrator is configuring an identity provider (IdP) for a new Software-as-a-Service (SaaS) application. The goal is to allow users to sign in once to their corporate network and then seamlessly access the SaaS application without re-entering credentials. Which protocol is MOST commonly used to achieve this single sign-on (SSO) functionality between an IdP and a service provider (SP)?
- ASAML
- BOAuth
- CHTTPS
- DLDAP
Show answer & explanationAnswer & explanation
Correct answer: A. SAML
SAML (Security Assertion Markup Language) is specifically designed for exchanging authentication and authorization data between an identity provider and a service provider, enabling single sign-on (SSO). It allows users to authenticate once with their corporate directory and then access multiple cloud applications.
Why the other options are wrong
- B. OAuth is an authorization framework that allows applications to obtain limited access to user accounts on an HTTP service, not primarily for SSO.
- C. HTTPS is a secure communication protocol over a computer network, providing encryption and integrity, but it is not an SSO protocol itself.
- D. LDAP is a protocol for accessing and maintaining distributed directory information services, not for federated SSO.
SAML (Security Assertion Markup Language)
An XML-based standard for exchanging authentication and authorization data between an identity provider (IdP) and a service provider (SP), enabling Single Sign-On (SSO).
- Enables Single Sign-On (SSO)
- Uses XML for assertions
- Commonly used for federated identity in cloud environments
Memory trick: SAML is like a digital passport for cloud apps.