Certified Cloud Security Professional (CCSP)Cloud Application SecurityMedium
A company is migrating its on-premises web application to a public cloud environment. The application uses a custom authentication system. To enhance security and provide a seamless user experience across multiple cloud services, the security architect proposes implementing a federated identity solution. Which of the following is a primary benefit of adopting federated identity in this scenario?
- AEliminates the need for strong password policies for end-users.
- BReduces the number of passwords users need to manage for different services.
- CProvides centralized logging and auditing for all application access.
- DAutomatically encrypts all data stored within the cloud application databases.
Show answer & explanationAnswer & explanation
Correct answer: B. Reduces the number of passwords users need to manage for different services.
Federated identity allows users to authenticate once with a trusted identity provider and gain access to multiple services without re-entering credentials, directly reducing the number of passwords users need to manage.
Why the other options are wrong
- A. Federated identity does not eliminate the need for strong password policies; the identity provider still requires them.
- C. While federated identity can integrate with centralized logging, its primary benefit is not centralized logging itself, but rather simplified access management.
- D. Federated identity is an authentication/authorization mechanism and does not directly provide data encryption for databases; that's a separate security control.
Federated Identity
A system that allows a user to authenticate with one identity provider and gain access to multiple independent systems or applications without needing to re-authenticate.
- Enables Single Sign-On (SSO).
- Relies on trusted identity providers.
- Improves user experience and reduces password management burden.
Memory trick: Federated Identity: 'One Key' to 'Many Doors'.