CompTIA SecurityX (CAS-005)Security ArchitectureHard

A security architect is integrating a legacy on-premises application with a new cloud-native microservices platform. The legacy application uses its own proprietary user directory, while the microservices platform relies on a modern identity provider (IdP). To provide a seamless single sign-on (SSO) experience for users accessing both environments and to centralize identity management, without migrating the legacy user directory, which identity component should be implemented?

  1. ACertificate Authority (CA)
  2. BIdentity Broker
  3. CDirectory Service
  4. DHardware Security Module (HSM)
Show answer & explanation

Correct answer: B. Identity Broker

An identity broker acts as an intermediary, translating identity information and authentication requests between different identity providers and service providers. It allows users authenticated against one system (e.g., the legacy directory) to access resources protected by another (e.g., the cloud IdP) without direct integration or migration, facilitating SSO and centralized management across disparate identity systems.

Why the other options are wrong

  • A. A Certificate Authority (CA) issues and manages digital certificates, unrelated to bridging different identity systems.
  • C. A directory service stores user identities but doesn't bridge incompatible identity systems for SSO.
  • D. An HSM provides secure storage for cryptographic keys but is not an identity management component.

Identity Broker

A service that mediates identity and authentication between multiple identity providers (IdPs) and service providers (SPs). It translates identity assertions and protocols, enabling single sign-on (SSO) across disparate systems without requiring direct integration.

  • Facilitates SSO across different identity systems.
  • Translates identity protocols (e.g., SAML, OAuth, OpenID Connect).
  • Decouples IdPs from SPs.
  • Manages identity federation and provisioning.

Memory trick: The Identity Broker is the translator that lets different identity systems talk to each other.

More Security Architecture questions