CompTIA SecurityX (CAS-005)Security EngineeringMedium
A security architect is designing an identity and access management (IAM) solution for a multinational corporation. The solution must support seamless single sign-on (SSO) across various cloud-based applications from different vendors while maintaining a high level of security and compliance with regional data residency requirements. Which IAM federation standard is BEST suited for this scenario?
- AOpenID Connect (OIDC)
- BOAuth 2.0
- CLightweight Directory Access Protocol (LDAP)
- DSecurity Assertion Markup Language (SAML)
Show answer & explanationAnswer & explanation
Correct answer: D. Security Assertion Markup Language (SAML)
SAML is an XML-based standard for exchanging authentication and authorization data between an identity provider and a service provider, making it ideal for enterprise SSO across disparate systems. It is robust and widely adopted for federated identity management in complex environments.
Why the other options are wrong
- A. OIDC is built on top of OAuth 2.0 and is primarily an authentication protocol, often used for user-facing applications and mobile apps, but SAML is more established for enterprise federation across diverse vendors.
- B. OAuth 2.0 is an authorization framework, not an authentication protocol, primarily used for granting delegated access to resources.
- C. LDAP is a protocol for accessing and maintaining distributed directory information services, typically used for local directory authentication, not for federated SSO across cloud services.
SAML (Security Assertion Markup Language)
An XML-based open standard for exchanging authentication and authorization data between an identity provider and a service provider, enabling single sign-on (SSO).
- XML-based protocol.
- Used for federated identity management.
- Enables Single Sign-On (SSO) across different security domains.
Memory trick: Federation's many standards, SAML for enterprise, OIDC for web, OAuth for access.