CompTIA SecurityX (CAS-005)Security EngineeringHard

A global software company is implementing a federated identity management system to allow employees to use their corporate credentials to access various third-party Software-as-a-Service (SaaS) applications. The system needs to support multiple identity providers and service providers, facilitate efficient user provisioning, and handle complex attribute mapping. Which protocol is MOST suitable for this complex enterprise-grade federation scenario?

  1. AOAuth 2.0
  2. BSAML 2.0
  3. CKerberos
  4. DOpenID Connect (OIDC)
Show answer & explanation

Correct answer: B. SAML 2.0

SAML 2.0 is an XML-based standard specifically designed for enterprise federated identity management, supporting complex scenarios with multiple identity providers and service providers, robust attribute exchange, and efficient user provisioning. While OIDC is gaining traction, SAML 2.0 remains a mature and widely adopted solution for such complex enterprise federations, especially with legacy SaaS applications.

Why the other options are wrong

  • A. OAuth 2.0 is an authorization framework, not an authentication protocol, and is used for granting delegated access, not federated identity for users.
  • C. Kerberos is a network authentication protocol for internal networks and does not support federated identity across disparate external organizations or SaaS providers.
  • D. OpenID Connect (OIDC) is an authentication layer on top of OAuth 2.0, primarily designed for modern web and mobile applications. While it supports federation, SAML 2.0 is often more robust and widely adopted for complex enterprise-to-enterprise (B2B) federations with extensive attribute requirements and provisioning.

SAML 2.0 (Security Assertion Markup Language)

An XML-based open standard for exchanging authentication and authorization data between an identity provider (IdP) and a service provider (SP) in enterprise federation scenarios.

  • Widely adopted for enterprise SSO and federation
  • Supports rich attribute exchange and complex scenarios
  • XML-based for secure data assertions

Memory trick: SAML 2.0: Securely Asserting Multi-domain Login!

More Security Engineering questions