CompTIA Cloud+ (CV0-004)SecurityMedium
A company is migrating its on-premises applications to a public cloud environment. The security team is concerned about ensuring that identity and access management (IAM) policies are consistently applied across both environments and that user provisioning/deprovisioning is automated. Which IAM solution would BEST address these concerns?
- AUsing a federated identity management system integrated with an on-premises identity provider.
- BManually configuring user accounts and permissions in each cloud environment.
- CRelying solely on cloud provider's built-in IAM roles for all users.
- DImplementing separate, native IAM solutions for each cloud provider.
Show answer & explanationAnswer & explanation
Correct answer: A. Using a federated identity management system integrated with an on-premises identity provider.
A federated identity management system integrated with an on-premises identity provider allows for consistent IAM policy application and automated provisioning/deprovisioning across hybrid cloud environments.
Why the other options are wrong
- B. Manual configuration is prone to errors, lacks consistency, and does not provide automation.
- C. Relying solely on built-in roles might not allow for integration with on-premises identity or automated provisioning/deprovisioning across hybrid environments.
- D. Separate native IAM solutions lead to inconsistency and manual overhead, failing to meet the requirements.
Federated Identity Management
A system that allows users to access multiple applications and services using a single set of login credentials, managed by a trusted identity provider, often spanning different security domains.
- Enables Single Sign-On (SSO).
- Promotes consistent policy enforcement.
- Simplifies user provisioning/deprovisioning across systems.
Memory trick: Federation: One ID to rule them all, on-prem and cloud.