CompTIA SecurityX (CAS-005)Security EngineeringEasy

A security architect is designing an authentication system for a new enterprise application. The application will be accessed by both internal employees and external partners, each using different identity providers. The architect wants to enable single sign-on (SSO) across these diverse identity stores while maintaining a high level of security and interoperability. Which of the following identity federation standards is BEST suited for this requirement?

  1. ALDAP
  2. BSAML
  3. CRADIUS
  4. DKerberos
Show answer & explanation

Correct answer: B. SAML

SAML (Security Assertion Markup Language) is an XML-based standard for exchanging authentication and authorization data between an identity provider and a service provider, making it ideal for federated identity management and SSO across disparate systems.

Why the other options are wrong

  • A. LDAP is a directory service protocol, not an identity federation standard for SSO between different organizations.
  • C. RADIUS is primarily used for centralized authentication, authorization, and accounting (AAA) for network access, not for web application SSO or identity federation.
  • D. Kerberos is a network authentication protocol that works within a trusted domain, not typically for cross-domain identity federation with external partners.

SAML (Security Assertion Markup Language)

An XML-based open standard for exchanging authentication and authorization data between an identity provider (IdP) and a service provider (SP). It enables single sign-on (SSO).

  • Uses XML for communication
  • Facilitates SSO across different security domains
  • Involves Identity Providers (IdP) and Service Providers (SP)

Memory trick: Federated identities link together, SAML is the key.

More Security Engineering questions