exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 471 discussion

Actual exam question from ISC's CISSP
Question #: 471
Topic #: 1
[All CISSP Questions]

When implementing single sign-on (SSO) on a network, which authentication approach BEST allows users to use credentials across multiple applications?

  • A. Public key infrastructure (PKI)
  • B. Security Assertion Markup Language (SAML)
  • C. Delegated Identity Management
  • D. Federated Identity Management
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Trap_D0_r
2 days, 23 hours ago
Selected Answer: D
As many have said, SAML is a protocol to implement FIM, but if you can read English the answer here is obviously FIM.
upvoted 1 times
...
M_S_L
1 month, 3 weeks ago
Selected Answer: D
🔹 Option Analysis B. Security Assertion Markup Language (SAML) SAML is a protocol used in SSO to pass authentication assertions between an identity provider (IdP) and service providers (SPs). It enables web-based SSO across apps. Very strong candidate, but it’s a protocol, not the overarching approach. ⚠️ Important piece, but not the "broad approach." D. Federated Identity Management (FIM) ✅ FIM is the approach that enables SSO across multiple systems, organizations, or applications by allowing trust relationships between IdPs and SPs. SAML (and OpenID Connect) are the technologies used within FIM. ✅ Correct. 👉 Memory Tip: FIM = approach (SSO across apps/orgs). SAML = protocol that enables it. OAuth/OIDC = delegation & federation for modern apps.
upvoted 2 times
...
khorma95
2 months, 3 weeks ago
Selected Answer: B
the answer is SAML. Federated Identity Management allows identities across different organizations/domains (trust relationships). Since its the same organization, the answer is SAML
upvoted 1 times
...
a_kto_to
6 months, 1 week ago
Selected Answer: D
Federated Identity Management (FIM) is the best approach for enabling users to authenticate once and access multiple applications across different domains or organizations.
upvoted 1 times
...
BigITGuy
8 months ago
Selected Answer: B
Can't be D. Federated Identity Management is a broader framework that may use SAML as a protocol, but the question specifically asks about the authentication approach, making SAML the best choice.
upvoted 1 times
...
andupro
10 months, 2 weeks ago
Selected Answer: B
SAML is for apps, federated is for the entire organization
upvoted 3 times
...
ch0udhary
1 year ago
Federation is across organizations, not applications in the same network.
upvoted 3 times
...
deeden
1 year, 3 months ago
Selected Answer: B
D. is a broader concept that encompasses SSO and allows users to access systems across different organizations using the same identity, typically implemented through SAML or OIDC.
upvoted 1 times
...
safri
1 year, 5 months ago
Selected Answer: B
I'm going with B, it says across an organization. SSO is within an organisation by using SAML whereas FIM is across multiple organisation according to my knowledge.
upvoted 2 times
...
dm808
1 year, 8 months ago
Selected Answer: D
FIM is an approach.. SAML is an implementation of FIM..
upvoted 2 times
...
Delab202
1 year, 9 months ago
Selected Answer: D
D. Federated Identity Management. Federated Identity Management systems allow the identities to be used across multiple IT systems or organizations, enabling users to log in once (Single Sign-On) and gain access to all associated systems without being prompted to log in again at each of them. This approach is particularly effective for SSO implementations because it establishes trust between different domains, allowing for the secure sharing of identity information across those domains. Security Assertion Markup Language (SAML) is a protocol used within Federated Identity Management to exchange authentication and authorization data, but Federated Identity Management itself is the broader approach that best facilitates SSO across multiple applications.
upvoted 4 times
...
YesPlease
1 year, 11 months ago
Selected Answer: B
Sorry, meant Answer B) SAML
upvoted 1 times
...
YesPlease
1 year, 11 months ago
Selected Answer: A
Answer A) SAML C and D are basically the same, just different scopes. SAML is the approach just like if you were to use OAUTH
upvoted 1 times
...
Soleandheel
1 year, 11 months ago
D. Security Assertion Markup Language (SAML): Federated Identity Management, on the other hand, typically applies when SSO needs to work across different organizations or domains. It involves multiple identity providers and service providers working together to enable SSO across organizational boundaries. So, in the context of a single organization's network, SAML is a strong choice for allowing users to use their credentials across multiple applications while maintaining security and convenience.
upvoted 1 times
...
Wz21
2 years ago
D. Federated Identity Management A. SAML is an XML-based standard for exchanging authentication and authorization data between parties, typically between an identity provider (IdP) and a service provider (SP). D. FIM involves the sharing of authentication and authorization across multiple trusted domains or systems.
upvoted 2 times
...
Wz21
2 years ago
D. Security Assertion Markup Language (SAML): How it works: SAML is an XML-based standard for exchanging authentication and authorization data between parties, typically between an identity provider (IdP) and a service provider (SP). FIM involves the sharing of authentication and authorization across multiple trusted domains or systems.
upvoted 1 times
...
printfmarcelo
2 years, 3 months ago
Selected Answer: B
B is correct
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...