CompTIA SecurityX (CAS-005)Security EngineeringHard

A global enterprise is implementing a Zero Trust architecture across its highly distributed network, which includes on-premises data centers, multiple cloud providers, and remote worker endpoints. A key challenge is establishing and verifying the identity of users and devices, and continuously evaluating their trustworthiness before granting access to resources. Which IAM protocol or framework is BEST suited to facilitate this continuous verification and dynamic policy enforcement across such a diverse and distributed environment?

  1. ALightweight Directory Access Protocol (LDAP)
  2. BOAuth 2.0 / OpenID Connect (OIDC)
  3. CSecurity Assertion Markup Language (SAML)
  4. DKerberos
Show answer & explanation

Correct answer: B. OAuth 2.0 / OpenID Connect (OIDC)

OAuth 2.0, primarily for authorization, combined with OpenID Connect (OIDC), for authentication, provides a flexible and extensible framework for identity and access management across diverse environments. Its token-based approach and ability to integrate with various identity providers make it ideal for continuous verification and dynamic policy enforcement in a Zero Trust model, especially with distributed cloud and remote access.

Why the other options are wrong

  • A. LDAP is a directory service protocol for storing and retrieving information, not an authentication or authorization protocol capable of dynamic policy enforcement across diverse environments.
  • C. SAML is an XML-based standard for exchanging authentication and authorization data, primarily used for single sign-on (SSO) in web-based enterprise applications, but OIDC offers more flexibility and is often preferred for modern cloud-native and mobile applications, especially with continuous verification needs.
  • D. Kerberos is primarily an authentication protocol for internal, on-premises networks and is not well-suited for distributed cloud or Zero Trust environments requiring continuous, dynamic verification.

OAuth 2.0 / OpenID Connect (OIDC)

OAuth 2.0 is an authorization framework allowing third-party applications to obtain limited access to an HTTP service. OpenID Connect (OIDC) is an identity layer built on top of OAuth 2.0, enabling clients to verify the identity of the end-user.

  • OAuth provides authorization, OIDC provides authentication.
  • Token-based (access tokens, ID tokens).
  • Widely used for federated identity and SSO in cloud/mobile.

Memory trick: OIDC Offers Identity for Distributed Clouds.

More Security Engineering questions