CompTIA SecurityX (CAS-005)Security ArchitectureMedium

A security architect is integrating a new cloud-based analytics platform with an existing on-premises Identity Provider (IdP). The goal is to allow users to authenticate once against the on-premises IdP and then seamlessly access the cloud analytics platform without re-entering credentials. The solution must support modern authentication protocols and avoid direct exposure of the on-premises IdP to the internet. Which component is BEST suited to facilitate this secure and seamless authentication process?

  1. AWeb Application Firewall (WAF).
  2. BLoad Balancer.
  3. CReverse Proxy.
  4. DIdentity Broker.
Show answer & explanation

Correct answer: D. Identity Broker.

An Identity Broker facilitates communication between different identity providers and service providers, translating authentication protocols and attributes. It enables Single Sign-On (SSO) across disparate systems (on-premises IdP and cloud SP) while abstracting the complexities and securely mediating the authentication flow without directly exposing the internal IdP.

Why the other options are wrong

  • A. A WAF protects web applications from attacks and can perform some authentication, but its primary role is not to mediate between different identity systems for SSO.
  • B. A Load Balancer distributes network traffic and can offer SSL termination, but it does not perform identity mediation or protocol translation for SSO.
  • C. A Reverse Proxy can provide a single entry point and some authentication, but it doesn't inherently translate authentication protocols or act as a mediator for SSO between distinct IdPs and SPs.

Identity Broker

An Identity Broker is an intermediary service that connects multiple identity providers (IdPs) and service providers (SPs), translating authentication requests and attributes between them to enable Single Sign-On (SSO) across disparate systems.

  • Facilitates SSO between different trust domains.
  • Translates identity protocols (e.g., SAML, OAuth, OIDC).
  • Abstracts complexity and enhances security by mediating access.
  • Often used in hybrid and multi-cloud environments.

Memory trick: An Identity Broker is like a 'universal translator' for identities, letting everyone speak the same language of trust.

More Security Architecture questions