CompTIA SecurityX (CAS-005)Security EngineeringEasy
A security architect is designing an authentication system for a new enterprise application that will integrate with multiple third-party services. The primary requirement is to enable single sign-on (SSO) across these services while ensuring strong identity verification. Which federated identity standard is BEST suited for this scenario, offering robust security features and broad interoperability?
- ASAML
- BLDAP
- CKerberos
- DRADIUS
Show answer & explanationAnswer & explanation
Correct answer: A. SAML
SAML is a widely adopted XML-based standard for exchanging authentication and authorization data between an identity provider and a service provider, making it ideal for federated SSO across disparate systems. It provides a secure and standardized way for users to access multiple applications with a single set of credentials.
Why the other options are wrong
- B. LDAP is a directory service protocol, not a federated identity standard for SSO.
- C. Kerberos is a network authentication protocol for internal networks, not typically used for federated SSO with external third-party services.
- D. RADIUS is primarily used for network access control and authentication, not for federated SSO across web applications.
SAML (Security Assertion Markup Language)
An XML-based standard for exchanging authentication and authorization data between an identity provider and a service provider, enabling single sign-on (SSO) for web applications.
- Enables Single Sign-On (SSO)
- Uses XML for data exchange
- Facilitates identity federation between different security domains
Memory trick: Fed up with logins? SAML's your single solution!