CompTIA SecurityX (CAS-005)Security EngineeringEasy
A security architect is designing an authentication system for a new enterprise application. The application will be accessed by both internal employees and external partners, each using different identity providers. The architect wants to enable single sign-on (SSO) across these diverse identity stores while maintaining a high level of security and interoperability. Which of the following identity federation standards is BEST suited for this requirement?
- ALDAP
- BSAML
- CRADIUS
- DKerberos
Show answer & explanationAnswer & explanation
Correct answer: B. SAML
SAML (Security Assertion Markup Language) is an XML-based standard for exchanging authentication and authorization data between an identity provider and a service provider, making it ideal for federated identity management and SSO across disparate systems.
Why the other options are wrong
- A. LDAP is a directory service protocol, not an identity federation standard for SSO between different organizations.
- C. RADIUS is primarily used for centralized authentication, authorization, and accounting (AAA) for network access, not for web application SSO or identity federation.
- D. Kerberos is a network authentication protocol that works within a trusted domain, not typically for cross-domain identity federation with external partners.
SAML (Security Assertion Markup Language)
An XML-based open standard for exchanging authentication and authorization data between an identity provider (IdP) and a service provider (SP). It enables single sign-on (SSO).
- Uses XML for communication
- Facilitates SSO across different security domains
- Involves Identity Providers (IdP) and Service Providers (SP)
Memory trick: Federated identities link together, SAML is the key.