CompTIA SecurityX (CAS-005)Security EngineeringMedium

A security architect is designing an authentication system for a new enterprise application. The application will be deployed across multiple cloud environments and needs to support a diverse set of user identities, including employees, partners, and customers, each managed by different identity providers. The architect wants to enable seamless, single sign-on (SSO) experiences while ensuring strong authentication and authorization across these disparate identity sources. Which of the following identity federation standards would be MOST appropriate for this scenario?

  1. ATACACS+
  2. BOpenID Connect (OIDC)
  3. CKerberos
  4. DLDAP
Show answer & explanation

Correct answer: B. OpenID Connect (OIDC)

OpenID Connect (OIDC) is built on top of OAuth 2.0 and provides an identity layer that enables clients to verify the identity of the end-user based on the authentication performed by an authorization server, as well as to obtain basic profile information about the end-user. This makes it ideal for federating identities across multiple providers and enabling SSO in diverse cloud environments.

Why the other options are wrong

  • A. TACACS+ is a proprietary Cisco protocol used for remote authentication and authorization, primarily for network device administration, not for application-level identity federation.
  • C. Kerberos is primarily a network authentication protocol for ticket-based authentication within a single domain, not suitable for cross-domain identity federation.
  • D. LDAP (Lightweight Directory Access Protocol) is a protocol for accessing and maintaining distributed directory information services, not an identity federation standard for SSO.

OpenID Connect (OIDC)

An identity layer built on top of the OAuth 2.0 protocol, allowing clients to verify the identity of an end-user based on the authentication performed by an authorization server, and to obtain basic profile information about the end-user.

  • Enables Single Sign-On (SSO)
  • Works across multiple identity providers (IdPs)
  • Provides identity verification and profile information
  • Built on OAuth 2.0

Memory trick: OIDC opens doors to seamless identity across clouds.

More Security Engineering questions