CompTIA SecurityX (CAS-005)Security EngineeringMedium

A security architect is designing an identity and access management (IAM) solution for a multi-cloud environment where users need to access applications hosted across different cloud providers and on-premises systems. The solution must provide single sign-on (SSO) capabilities and allow for standardized attribute exchange to facilitate authorization decisions. Which federation standard is BEST suited for this scenario?

  1. ALightweight Directory Access Protocol (LDAP)
  2. BOAuth 2.0
  3. CSecurity Assertion Markup Language (SAML)
  4. DOpenID Connect (OIDC)
Show answer & explanation

Correct answer: C. Security Assertion Markup Language (SAML)

Security Assertion Markup Language (SAML) is an XML-based standard for exchanging authentication and authorization data between an identity provider (IdP) and a service provider (SP). It is widely adopted in enterprise environments for federated identity and single sign-on (SSO) across disparate systems, including multi-cloud and on-premises applications, and supports robust attribute exchange.

Why the other options are wrong

  • A. LDAP is a directory service protocol for storing and retrieving identity information, not an identity federation or SSO standard.
  • B. OAuth 2.0 is an authorization framework (delegated authorization), not an authentication protocol, and does not provide identity assertions for SSO directly.
  • D. OIDC is built on OAuth 2.0 and provides identity verification, often preferred for consumer-facing apps, but SAML is more prevalent and robust for enterprise federation.

SAML (Security Assertion Markup Language)

An XML-based open standard for exchanging authentication and authorization data between an identity provider (IdP) and a service provider (SP), enabling federated single sign-on (SSO) in enterprise environments.

  • XML-based protocol.
  • Used for federated SSO and attribute exchange.
  • Common in enterprise and multi-cloud scenarios.

Memory trick: SAML is the Enterprise XML for SSO.

More Security Engineering questions