CompTIA SecurityX (CAS-005)Security ArchitectureMedium
A security architect is integrating a legacy on-premises application with a new cloud-native microservices platform. The legacy application relies on Active Directory for authentication, while the cloud platform uses OIDC (OpenID Connect) with an external identity provider. Which component is essential for securely bridging these two distinct identity management systems?
- AIdentity Broker
- BCloud Access Security Broker (CASB)
- CSecurity Information and Event Management (SIEM)
- DData Loss Prevention (DLP) Gateway
Show answer & explanationAnswer & explanation
Correct answer: A. Identity Broker
An identity broker acts as an intermediary service that translates identity assertions and protocols between different identity providers and service providers. This allows the legacy Active Directory users to authenticate and gain access to cloud resources that expect OIDC tokens.
Why the other options are wrong
- B. CASBs provide security policies for cloud application usage, but do not directly bridge different authentication protocols like AD and OIDC.
- C. SIEM systems aggregate and analyze security logs, which is for monitoring, not for bridging identity protocols.
- D. DLP Gateways focus on preventing sensitive data from leaving the organization, not on identity federation.
Identity Broker
A service that acts as an intermediary, translating identity information and authentication protocols between different identity providers and service providers.
- Enables Single Sign-On (SSO) across heterogeneous identity systems.
- Supports various protocols like SAML, OAuth, OIDC, LDAP.
- Simplifies identity management in hybrid and multi-cloud environments.
Memory trick: Hybrid identity needs a 'translator' to make different 'languages' of authentication understand each other.