Certified Information Systems Security Professional CISSP · Free Practice Question Medium
Question 54
An enterprise organization is deploying a cloud-based customer portal and wants users to log in using their existing corporate credentials. Which of the following identity federation technologies is BEST suited for this scenario?
- A OAuth 2.0.
- B OpenID Connect (OIDC).
- C Security Assertion Markup Language (SAML).
- D Kerberos.
Reveal correct answer
Correct answer: C
Explanation
OBJ. 5.3 - SAML is best suited for enterprise Single Sign-On (SSO), enabling users to log in once and access multiple applications using corporate identity providers (e.g., Active Directory Federation Services). OpenID Connect (A) is optimized for consumer-facing web apps rather than enterprise environments. OAuth 2.0 (B) is an authorization framework, not an authentication protocol. Kerberos (D) is used for authentication within internal enterprise networks, not for cloud-based SSO. For support or reporting issues, include Question ID: 67d96855c59c26a80470d58a in your ticket. Thank you.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
