ISC2 CISSP (Certified Information Systems Security Professional)Identity and Access Management (IAM)Easy
A project manager is concerned about the security implications of integrating an external vendor's cloud-based application with the company's internal services. The vendor proposes using Security Assertion Markup Language (SAML) for user authentication and authorization between the two environments. What primary benefit does SAML offer in this scenario?
- AIt mandates the use of specific cryptographic algorithms for communication.
- BIt provides strong encryption for all data transmitted between systems.
- CIt enables a single sign-on (SSO) experience for users across domains.
- DIt enforces multi-factor authentication (MFA) automatically.
Show answer & explanationAnswer & explanation
Correct answer: C. It enables a single sign-on (SSO) experience for users across domains.
SAML's primary purpose is to facilitate secure exchange of authentication and authorization data, enabling single sign-on (SSO) across different security domains. This allows users to authenticate once with their identity provider and gain access to multiple service providers.
Why the other options are wrong
- A. SAML doesn't mandate specific cryptographic algorithms, though it recommends certain practices and relies on underlying security protocols.
- B. SAML itself does not provide encryption for *all* data; it relies on underlying transport security like TLS/SSL for secure communication.
- D. SAML does not automatically enforce MFA; MFA is typically implemented at the identity provider level.
Security Assertion Markup Language (SAML)
SAML is an XML-based open standard for exchanging authentication and authorization data between an identity provider and a service provider.
- Enables Single Sign-On (SSO).
- Uses XML for assertions.
- Commonly used for federated identity management.
Memory trick: SAML Makes Life Simple (SSO).