CompTIA SecurityX (CAS-005)Security EngineeringEasy
A security architect is designing an identity and access management (IAM) solution for a large enterprise that uses multiple cloud providers and on-premises applications. The goal is to provide a single, unified identity for users across all services, minimizing administrative overhead and improving security posture. Which of the following IAM frameworks is BEST suited for this requirement?
- ARole-Based Access Control (RBAC)
- BIdentity Federation
- CAttribute-Based Access Control (ABAC)
- DMandatory Access Control (MAC)
Show answer & explanationAnswer & explanation
Correct answer: B. Identity Federation
Identity federation allows users to use a single set of credentials to access multiple, independent systems across different security domains. This directly addresses the need for a unified identity across multiple cloud providers and on-premises applications, reducing administrative overhead.
Why the other options are wrong
- A. RBAC defines permissions based on roles within a single system or domain, not across disparate systems.
- C. ABAC grants access based on attributes of the user, resource, and environment, which is a fine-grained authorization model, but doesn't inherently unify identities across domains.
- D. MAC is a strict access control model often used in high-security environments, but it does not provide for identity unification across disparate systems.
Identity Federation
A system that allows users to use the same digital identity across multiple, independent application systems or organizations, enabling single sign-on (SSO).
- Enables single sign-on (SSO)
- Reduces administrative burden
- Improves user experience across disparate systems
Memory trick: Federation is like a universal passport for your digital identity.