CompTIA SecurityX (CAS-005)Security EngineeringMedium

A security architect is designing an identity and access management (IAM) solution for a multinational corporation. The solution must support seamless single sign-on (SSO) across various cloud-based applications from different vendors while maintaining a high level of security and compliance with regional data residency requirements. Which IAM federation standard is BEST suited for this scenario?

  1. AOpenID Connect (OIDC)
  2. BOAuth 2.0
  3. CLightweight Directory Access Protocol (LDAP)
  4. DSecurity Assertion Markup Language (SAML)
Show answer & explanation

Correct answer: D. Security Assertion Markup Language (SAML)

SAML is an XML-based standard for exchanging authentication and authorization data between an identity provider and a service provider, making it ideal for enterprise SSO across disparate systems. It is robust and widely adopted for federated identity management in complex environments.

Why the other options are wrong

  • A. OIDC is built on top of OAuth 2.0 and is primarily an authentication protocol, often used for user-facing applications and mobile apps, but SAML is more established for enterprise federation across diverse vendors.
  • B. OAuth 2.0 is an authorization framework, not an authentication protocol, primarily used for granting delegated access to resources.
  • C. LDAP is a protocol for accessing and maintaining distributed directory information services, typically used for local directory authentication, not for federated SSO across cloud services.

SAML (Security Assertion Markup Language)

An XML-based open standard for exchanging authentication and authorization data between an identity provider and a service provider, enabling single sign-on (SSO).

  • XML-based protocol.
  • Used for federated identity management.
  • Enables Single Sign-On (SSO) across different security domains.

Memory trick: Federation's many standards, SAML for enterprise, OIDC for web, OAuth for access.

More Security Engineering questions