ISC2 CISSP (Certified Information Systems Security Professional)Identity and Access Management (IAM)Hard

A software development company is adopting a DevOps culture and needs to manage access for automated processes and microservices without using traditional user credentials. They require a secure method for these non-human entities to authenticate and obtain authorization to interact with other services and resources. Which protocol or framework is MOST appropriate for this scenario?

  1. ASAML
  2. BOAuth 2.0 / OpenID Connect
  3. CKerberos
  4. DRADIUS
Show answer & explanation

Correct answer: B. OAuth 2.0 / OpenID Connect

OAuth 2.0 is an authorization framework designed for delegated access, making it suitable for service-to-service communication using client credentials or other grant types without human interaction. OpenID Connect builds on OAuth 2.0 to add an identity layer, providing authentication for these non-human entities if identity verification is also needed.

Why the other options are wrong

  • A. SAML is an XML-based standard for web-browser SSO, typically for human users interacting with web applications, not ideal for machine-to-machine authorization.
  • C. Kerberos is primarily for authenticating human users within a single domain, using a ticket-based system, less flexible for microservices and API access.
  • D. RADIUS is a protocol for network access authentication, authorization, and accounting, not designed for API-based service-to-service authentication and authorization in a cloud-native environment.

OAuth 2.0 / OpenID Connect (OIDC)

OAuth 2.0 is an authorization framework for delegated access. OpenID Connect is an identity layer built on top of OAuth 2.0, providing authentication.

  • OAuth: Authorization for APIs and service-to-service.
  • OIDC: Adds identity verification to OAuth.
  • Widely used for modern web, mobile, and microservice architectures.

Memory trick: OAuth/OIDC for API Bots' Access Control

More Identity and Access Management (IAM) questions