Certified Information Systems Security Professional CISSP · Free Practice Question Easy
Question 46
Leilani chose Security Assertion Markup Language (SAML) for our federated identity management (FIdM). Which type of Single Sign-On (SSO) is that?
- A Spoke SSO
- B Basic SSO
- C Third-party SSO
- D Federated SSO
Reveal correct answer
Correct answer: D
Explanation
The correct answer: Federated Single Sign-On (SSO) is the correct answer because it aligns with the concept of federated identity management. In this approach, organizations share a trust relationship and agree on an interoperable standard for exchanging authentication and authorization data. Security Assertion Markup Language (SAML) is one such standard commonly used in federated SSO systems. SAML allows for secure exchange of user authentication data across different networks, making it easier to manage identities across multiple systems or organizations. The incorrect answers: Basic Single Sign-On (SSO) allows a user to sign in once and gain access to multiple systems without needing to sign in again at each of them. While SAML can be used in Basic SSO, this choice is not the best answer. Basic SSO generally pertains to systems within the same organization, not across federated identities from different organizations. Hence, it does not fully encapsulate the idea of federated identity management that SAML embodies. Third-party SSO refers to situations where authentication is delegated to a third-party service, such as Google or Facebook, that many users already have accounts with. While SAML could theoretically be used by a third-party SSO service, its main purpose is not for third-party SSO, but rather for federated SSO across different organizations or systems. Therefore, this option is not the best fit for the question. Spoke SSO is a less common term and might be used to describe a hub-and-spoke architecture where one primary (hub) application handles authentication and other (spoke) applications rely on the hub for user authentication information. While SAML could be used in such a setup, it is not specific or inherent to a "Spoke SSO" system. Again, the focus of SAML is on facilitating federated identity management, making the "Federated SSO" option the most suitable answer.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
