CompTIA Cloud+ (CV0-004)SecurityMedium
A cloud security architect is integrating a third-party SaaS application with the company's internal identity provider (IdP). The goal is to allow users to log in to the SaaS application using their existing corporate credentials without creating new accounts, while also enabling centralized access management and de-provisioning. Which protocol is most commonly used to achieve this single sign-on (SSO) and identity federation securely?
- ASAML
- BSSH
- CKerberos
- DLDAP
Show answer & explanationAnswer & explanation
Correct answer: A. SAML
SAML (Security Assertion Markup Language) is an XML-based standard for exchanging authentication and authorization data between an identity provider (IdP) and a service provider (SP). It is widely used to achieve single sign-on (SSO) and identity federation, allowing users to access SaaS applications with their corporate credentials.
Why the other options are wrong
- B. SSH (Secure Shell) is a cryptographic network protocol for secure remote access to computers, not for identity federation or SSO.
- C. Kerberos is an authentication protocol commonly used in Windows domains for single sign-on within a local network, but not typically for federating identities to external SaaS applications.
- D. LDAP (Lightweight Directory Access Protocol) is primarily used for querying and modifying directory services, not for federated identity or SSO across different domains.
SAML (Security Assertion Markup Language)
An XML-based open standard for exchanging authentication and authorization data between an identity provider and a service provider, enabling single sign-on (SSO).
- XML-based protocol
- Enables SSO and identity federation
- Exchanges auth/auth data between IdP and SP
Memory trick: SAML is the universal translator for cloud identity login.