CompTIA SecurityX (CAS-005)Security EngineeringEasy
A security architect is designing an identity and access management (IAM) solution for a multi-cloud environment. The solution needs to provide centralized authentication and authorization services for applications deployed across different cloud providers, allowing users to log in once and access multiple services without re-entering credentials. Which of the following protocols is BEST suited for this requirement?
- ALDAP
- BKerberos
- CRADIUS
- DSAML
Show answer & explanationAnswer & explanation
Correct answer: D. SAML
SAML is an XML-based standard for exchanging authentication and authorization data between an identity provider and a service provider, making it ideal for single sign-on (SSO) across disparate systems and cloud environments.
Why the other options are wrong
- A. LDAP is a protocol for accessing and maintaining distributed directory information services, not primarily for federated identity or SSO across different domains.
- B. Kerberos is a network authentication protocol that works well within a single domain but is less suited for cross-domain or multi-cloud SSO without complex trust relationships.
- C. RADIUS is primarily used for centralized authentication, authorization, and accounting (AAA) for network access, not for application-level SSO in a multi-cloud environment.
SAML (Security Assertion Markup Language)
An XML-based open standard for exchanging authentication and authorization data between an identity provider and a service provider, enabling single sign-on (SSO).
- Enables Single Sign-On (SSO)
- Uses XML for assertions
- Facilitates identity federation across security domains
Memory trick: SAM's XML Assertions Unite Clouds for SSO.