CompTIA SecurityX (CAS-005)Security ArchitectureMedium

A security architect is integrating a new cloud-based analytics platform with an existing on-premises Human Resources (HR) system. The HR system uses a proprietary identity store, while the analytics platform requires SAML 2.0 for user authentication. The architect needs a solution that can translate authentication requests and assertions between these disparate identity providers and service providers without requiring direct integration between each system. Which architectural component would fulfill this role?

  1. AIdentity Broker
  2. BSecurity Assertion Markup Language (SAML) Gateway
  3. CCertificate Authority (CA)
  4. DDirectory Service (e.g., LDAP)
Show answer & explanation

Correct answer: A. Identity Broker

An Identity Broker acts as an intermediary service that translates identity assertions and protocols between different identity providers and service providers. This is ideal for connecting a proprietary on-premises HR identity store with a cloud platform requiring SAML, without direct integration.

Why the other options are wrong

  • B. While SAML is a protocol, a 'SAML Gateway' is not a standard architectural component that performs the broader translation required between entirely different identity protocols and stores. An Identity Broker can handle SAML along with other protocols.
  • C. A Certificate Authority issues and manages digital certificates for public key infrastructure; it is not involved in translating identity protocols.
  • D. A Directory Service like LDAP stores user identities and attributes, but it does not translate authentication protocols between different systems.

Identity Broker

An Identity Broker is an intermediary service that connects multiple identity providers to multiple service providers. It translates authentication requests and assertions between different security domains, enabling single sign-on (SSO) and simplified identity management across disparate systems.

  • Acts as a mediator between Identity Providers (IdPs) and Service Providers (SPs).
  • Translates authentication protocols (e.g., SAML, OAuth, OpenID Connect, proprietary).
  • Simplifies identity integration in hybrid and multi-cloud environments.
  • Enables single sign-on (SSO) for users across different applications.

Memory trick: Identity Broker Bridges Between Big Identity Realms.

More Security Architecture questions