ISC2 CISSP (Certified Information Systems Security Professional)Identity and Access Management (IAM)Medium
A large organization is migrating its legacy on-premise applications to a cloud-native architecture. They need a solution that can manage user identities and access across both on-premise and multiple cloud environments, providing a unified single sign-on experience. Which of the following identity services BEST addresses this hybrid cloud requirement?
- ASecurity Information and Event Management (SIEM)
- BIdentity as a Service (IDaaS)
- CLightweight Directory Access Protocol (LDAP)
- DActive Directory Federation Services (AD FS)
Show answer & explanationAnswer & explanation
Correct answer: B. Identity as a Service (IDaaS)
IDaaS solutions are designed to provide identity and access management capabilities as a cloud service, supporting hybrid environments by integrating with on-premise directories and offering unified SSO across various cloud applications.
Why the other options are wrong
- A. SIEM is a security system for collecting and analyzing logs, not an identity and access management service.
- C. LDAP is a protocol for accessing directory services, not a comprehensive identity management solution for hybrid cloud SSO.
- D. AD FS is a Microsoft solution primarily for federating Active Directory identities, often used for on-premise to cloud, but IDaaS offers a broader, vendor-agnostic approach for multi-cloud and hybrid environments.
Identity as a Service (IDaaS)
A cloud-based offering that provides identity and access management (IAM) capabilities as a service, including authentication, authorization, and user management.
- Delivered as a cloud service.
- Supports single sign-on (SSO).
- Manages identities across on-premise and multiple cloud applications.
Memory trick: IDaaS Connects On-Prem to Clouds with Ease