ISC2 CISSP (Certified Information Systems Security Professional)Identity and Access Management (IAM)Easy
A multinational corporation is expanding its operations and requires a standardized, federated identity management solution to allow employees seamless access to resources across different subsidiaries and cloud services, without requiring multiple credentials. Which of the following technologies is BEST suited to achieve this goal?
- ARemote Authentication Dial-In User Service (RADIUS)
- BLightweight Directory Access Protocol (LDAP)
- CKerberos
- DSecurity Assertion Markup Language (SAML)
Show answer & explanationAnswer & explanation
Correct answer: D. Security Assertion Markup Language (SAML)
SAML is an XML-based framework for exchanging authentication and authorization data between security domains, making it ideal for federated identity management and single sign-on across disparate systems and organizations.
Why the other options are wrong
- A. RADIUS is a networking protocol that provides centralized Authentication, Authorization, and Accounting (AAA) management for users connecting to a network service, typically for network access control.
- B. LDAP is a protocol for accessing and maintaining distributed directory information services, primarily used for centralizing user directories, not for federated identity across different domains.
- C. Kerberos is a network authentication protocol that works on a ticket-based system within a single domain, not federated across multiple organizations or cloud services.
SAML (Security Assertion Markup Language)
An open standard for exchanging authentication and authorization data between an identity provider and a service provider, enabling single sign-on (SSO).
- XML-based protocol.
- Facilitates federated identity.
- Supports web-based authentication.
Memory trick: Seamless Access Links Global Domains