SSCP Systems Security Certified PractitionerAccess ControlsMedium

An organization is implementing a new authentication system that allows users to log in once to access multiple independent software systems without re-entering their credentials. This system relies on a central identity provider and security tokens. What is this authentication concept called?

  1. ABiometric authentication
  2. BSingle Sign-On (SSO)
  3. CFederated identity management
  4. DMulti-factor authentication (MFA)
Show answer & explanation

Correct answer: B. Single Sign-On (SSO)

Single Sign-On (SSO) is an authentication scheme that allows a user to log in with a single ID and password to gain access to a connected system or systems without using different usernames or passwords.

Why the other options are wrong

  • A. Biometric authentication uses unique biological traits, not a single login for multiple systems.
  • C. Federated identity management is a broader concept that enables SSO across different security domains, but SSO is the specific mechanism for 'one login, multiple systems'.
  • D. MFA requires multiple authentication factors, but doesn't inherently imply access to multiple systems with one login.

Single Sign-On (SSO)

An authentication process that allows a user to access multiple independent software systems using a single set of login credentials.

  • Enhances user convenience by eliminating repeated logins.
  • Can improve security by centralizing authentication and reducing password fatigue.
  • Often implemented using protocols like SAML or OAuth.

Memory trick: IAM's goal: One key opens many doors.

More Access Controls questions