ISC2 CISSP (Certified Information Systems Security Professional)Identity and Access Management (IAM)Hard
A software development company is adopting a DevOps culture and needs to manage access for automated processes and microservices without using traditional user credentials. They require a secure method for these non-human entities to authenticate and obtain authorization to interact with other services and resources. Which protocol or framework is MOST appropriate for this scenario?
- ASAML
- BOAuth 2.0 / OpenID Connect
- CKerberos
- DRADIUS
Show answer & explanationAnswer & explanation
Correct answer: B. OAuth 2.0 / OpenID Connect
OAuth 2.0 is an authorization framework designed for delegated access, making it suitable for service-to-service communication using client credentials or other grant types without human interaction. OpenID Connect builds on OAuth 2.0 to add an identity layer, providing authentication for these non-human entities if identity verification is also needed.
Why the other options are wrong
- A. SAML is an XML-based standard for web-browser SSO, typically for human users interacting with web applications, not ideal for machine-to-machine authorization.
- C. Kerberos is primarily for authenticating human users within a single domain, using a ticket-based system, less flexible for microservices and API access.
- D. RADIUS is a protocol for network access authentication, authorization, and accounting, not designed for API-based service-to-service authentication and authorization in a cloud-native environment.
OAuth 2.0 / OpenID Connect (OIDC)
OAuth 2.0 is an authorization framework for delegated access. OpenID Connect is an identity layer built on top of OAuth 2.0, providing authentication.
- OAuth: Authorization for APIs and service-to-service.
- OIDC: Adds identity verification to OAuth.
- Widely used for modern web, mobile, and microservice architectures.
Memory trick: OAuth/OIDC for API Bots' Access Control