Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cloud SecurityHard
A multinational corporation is adopting a hybrid cloud strategy, utilizing both their on-premises data centers and a public cloud provider. They need to ensure seamless and secure identity management across both environments, allowing users to authenticate once and access resources in either location without re-entering credentials. Which cloud security best practice addresses this requirement?
- AConducting regular security audits and compliance checks.
- BImplementing a centralized logging and monitoring solution.
- CUtilizing federated identity management.
- DEnforcing data encryption for all data at rest and in transit.
Show answer & explanationAnswer & explanation
Correct answer: C. Utilizing federated identity management.
Federated identity management allows a single set of credentials to be used across multiple, disparate systems or organizations. In a hybrid cloud context, this enables users to authenticate against their on-premises identity provider (e.g., Active Directory) and gain seamless access to resources in the public cloud, achieving single sign-on (SSO).
Why the other options are wrong
- A. Security audits assess compliance but do not implement the technical solution for identity federation.
- B. Centralized logging aids in security visibility but does not manage user identities or achieve SSO.
- D. Data encryption protects data confidentiality but is unrelated to single sign-on or identity federation.
Federated Identity Management
A system that allows users to authenticate once with a trusted identity provider and then gain access to multiple independent systems or applications without re-authenticating (Single Sign-On). Essential for hybrid and multi-cloud environments.
- Enables Single Sign-On (SSO).
- Reduces administrative burden and improves user experience.
- Commonly uses standards like SAML or OIDC.
Memory trick: Federated Identity is like a 'F'ast 'I'dentity 'M'over across clouds.