Cisco CCNP Security Core (SCOR) 350-701Cloud SecurityMedium
A security architect is integrating an on-premises Active Directory with a cloud-based Software as a Service (SaaS) application to provide single sign-on (SSO) capabilities. The goal is to allow users to authenticate once using their existing corporate credentials and access the SaaS application without re-entering them. Which protocol is commonly used to facilitate this federated identity management in cloud environments?
- ASMTP
- BSSH
- CSNMP
- DSAML
Show answer & explanationAnswer & explanation
Correct answer: D. SAML
SAML (Security Assertion Markup Language) is an XML-based open standard for exchanging authentication and authorization data between an identity provider (like Active Directory) and a service provider (like a SaaS application). It is widely used for federated single sign-on.
Why the other options are wrong
- A. SMTP (Simple Mail Transfer Protocol) is used for sending email, not for identity federation.
- B. SSH (Secure Shell) is used for secure remote access to systems, not for single sign-on.
- C. SNMP (Simple Network Management Protocol) is used for network device management, not identity federation.
SAML (Security Assertion Markup Language)
An XML-based standard for exchanging authentication and authorization data between security domains.
- Enables Single Sign-On (SSO) for web applications.
- Used for federated identity management.
- Involves an Identity Provider (IdP) and a Service Provider (SP).
Memory trick: SAML: Seamless Access for Many Logins.