CompTIA SecurityX (CAS-005)Security ArchitectureMedium
A security architect is integrating a legacy on-premises application with a new cloud-native microservices platform. The legacy application uses its own user store, while the microservices platform relies on a modern identity provider. To enable single sign-on (SSO) and consistent user experience across both environments without migrating the legacy user store, which architectural component should be implemented?
- ASecurity Information and Event Management (SIEM)
- BIdentity Broker
- CAPI Gateway
- DLDAP directory server
Show answer & explanationAnswer & explanation
Correct answer: B. Identity Broker
An Identity Broker acts as an intermediary, translating identity assertions and protocols between different identity providers and service providers, enabling SSO and linking disparate identity systems without requiring migration of user stores.
Why the other options are wrong
- A. SIEM is for collecting and analyzing security logs, irrelevant to identity integration for SSO.
- C. An API Gateway manages API traffic and enforces policies but does not primarily handle identity protocol translation between different identity stores.
- D. An LDAP directory server is a user store itself, not a component for mediating between different identity systems.
Identity Broker
A service that acts as an intermediary between an Identity Provider (IdP) and a Service Provider (SP), translating identity assertions and protocols to enable single sign-on (SSO) across different identity systems.
- Enables SSO across disparate identity stores.
- Translates identity protocols (e.g., SAML, OIDC).
- Reduces complexity of integrating multiple IdPs.
Memory trick: Identity Broker: 'Bridges Identity Gaps' between old and new.