CompTIA SecurityX (CAS-005)Security EngineeringEasy

A security architect is designing an identity and access management (IAM) solution for a large enterprise that uses multiple cloud providers and on-premises applications. The goal is to provide a single, unified identity for users across all services, minimizing administrative overhead and improving security posture. Which of the following IAM frameworks is BEST suited for this requirement?

  1. ARole-Based Access Control (RBAC)
  2. BIdentity Federation
  3. CAttribute-Based Access Control (ABAC)
  4. DMandatory Access Control (MAC)
Show answer & explanation

Correct answer: B. Identity Federation

Identity federation allows users to use a single set of credentials to access multiple, independent systems across different security domains. This directly addresses the need for a unified identity across multiple cloud providers and on-premises applications, reducing administrative overhead.

Why the other options are wrong

  • A. RBAC defines permissions based on roles within a single system or domain, not across disparate systems.
  • C. ABAC grants access based on attributes of the user, resource, and environment, which is a fine-grained authorization model, but doesn't inherently unify identities across domains.
  • D. MAC is a strict access control model often used in high-security environments, but it does not provide for identity unification across disparate systems.

Identity Federation

A system that allows users to use the same digital identity across multiple, independent application systems or organizations, enabling single sign-on (SSO).

  • Enables single sign-on (SSO)
  • Reduces administrative burden
  • Improves user experience across disparate systems

Memory trick: Federation is like a universal passport for your digital identity.

More Security Engineering questions