SSCP Systems Security Certified PractitionerAccess ControlsMedium
An organization is implementing a new authentication system that allows users to log in once to access multiple independent software systems without re-entering their credentials. This system relies on a central identity provider and security tokens. What is this authentication concept called?
- ABiometric authentication
- BSingle Sign-On (SSO)
- CFederated identity management
- DMulti-factor authentication (MFA)
Show answer & explanationAnswer & explanation
Correct answer: B. Single Sign-On (SSO)
Single Sign-On (SSO) is an authentication scheme that allows a user to log in with a single ID and password to gain access to a connected system or systems without using different usernames or passwords.
Why the other options are wrong
- A. Biometric authentication uses unique biological traits, not a single login for multiple systems.
- C. Federated identity management is a broader concept that enables SSO across different security domains, but SSO is the specific mechanism for 'one login, multiple systems'.
- D. MFA requires multiple authentication factors, but doesn't inherently imply access to multiple systems with one login.
Single Sign-On (SSO)
An authentication process that allows a user to access multiple independent software systems using a single set of login credentials.
- Enhances user convenience by eliminating repeated logins.
- Can improve security by centralizing authentication and reducing password fatigue.
- Often implemented using protocols like SAML or OAuth.
Memory trick: IAM's goal: One key opens many doors.