Certified Cloud Security Professional (CCSP)Cloud Concepts, Architecture and DesignMedium
A large enterprise is considering a hybrid cloud strategy. They need to ensure seamless identity management across their on-premises Active Directory and multiple public cloud providers. Which security best practice should be prioritized to achieve this goal?
- ADeploying a comprehensive Cloud Access Security Broker (CASB).
- BEnforcing strong encryption for all data in transit.
- CImplementing a robust Data Loss Prevention (DLP) solution.
- DEstablishing a federated identity management system.
Show answer & explanationAnswer & explanation
Correct answer: D. Establishing a federated identity management system.
Federated identity management allows a single set of credentials to be used across multiple, disparate systems and providers, which is essential for seamless identity management in a hybrid cloud environment.
Why the other options are wrong
- A. A CASB provides visibility and control over cloud application usage, but doesn't directly manage identity federation.
- B. Encryption protects data, but doesn't solve the problem of managing user identities across different platforms.
- C. DLP focuses on preventing data exfiltration, not identity synchronization.
Federated Identity Management
A system that allows users to use a single identity across multiple, disparate applications or services from different providers, without needing to re-authenticate.
- Enables Single Sign-On (SSO) across organizational boundaries.
- Relies on trust relationships between identity providers and service providers.
- Common protocols include SAML, OAuth, and OpenID Connect.
Memory trick: Federated identity is like a universal passport for all your cloud travels.