ISC2 CISSP (Certified Information Systems Security Professional)Identity and Access Management (IAM)Medium

A large organization is migrating its legacy on-premise applications to a cloud-native architecture. They need a solution that can manage user identities and access across both on-premise and multiple cloud environments, providing a unified single sign-on experience. Which of the following identity services BEST addresses this hybrid cloud requirement?

  1. ASecurity Information and Event Management (SIEM)
  2. BIdentity as a Service (IDaaS)
  3. CLightweight Directory Access Protocol (LDAP)
  4. DActive Directory Federation Services (AD FS)
Show answer & explanation

Correct answer: B. Identity as a Service (IDaaS)

IDaaS solutions are designed to provide identity and access management capabilities as a cloud service, supporting hybrid environments by integrating with on-premise directories and offering unified SSO across various cloud applications.

Why the other options are wrong

  • A. SIEM is a security system for collecting and analyzing logs, not an identity and access management service.
  • C. LDAP is a protocol for accessing directory services, not a comprehensive identity management solution for hybrid cloud SSO.
  • D. AD FS is a Microsoft solution primarily for federating Active Directory identities, often used for on-premise to cloud, but IDaaS offers a broader, vendor-agnostic approach for multi-cloud and hybrid environments.

Identity as a Service (IDaaS)

A cloud-based offering that provides identity and access management (IAM) capabilities as a service, including authentication, authorization, and user management.

  • Delivered as a cloud service.
  • Supports single sign-on (SSO).
  • Manages identities across on-premise and multiple cloud applications.

Memory trick: IDaaS Connects On-Prem to Clouds with Ease

More Identity and Access Management (IAM) questions