Soru

Zorluk: OrtaIdentity and Access Management Architecture

An organization is updating its enterprise access architecture to grant external partner employees access to web applications hosted in a private cloud. The security team requires a federated identity solution that allows partners to authenticate using their own Identity Provider (IdP) and transmit digitally signed XML security assertions to the relying application without syncing credentials or exposing internal directory endpoints. Which of the following identity standards should the security team implement?

  1. Security Assertion Markup Language (SAML)Cevap
  2. B
    Remote Authentication Dial-In User Service (RADIUS)
  3. C
    Lightweight Directory Access Protocol over TLS (LDAPS)
  4. D
    Kerberos with cross-realm trust

Cevap

Security Assertion Markup Language (SAML) is the correct selection because it uses digitally signed XML tokens transmitted over HTTP to establish cross-organizational web single sign-on without sharing account passwords.
Security Assertion Markup Language (SAML) is the standard protocol for web-based federated single sign-on (SSO). It allows an Identity Provider (IdP) to authenticate a user and securely pass digitally signed XML security assertions to a Service Provider (SP) via standard HTTP browser redirections, enabling secure cross-organizational access without sharing or synchronizing user credentials.

Adım Adım Çözüm

1
Analyze the functional requirements of the identity architecture scenario.
The scenario requires cross-organizational federation, web application support, use of digitally signed XML assertions, and zero user credential synchronization.
Identifying protocol requirements filters out legacy network AAA and centralized directory query protocols.
2
Evaluate candidate protocols against XML assertion and web federation criteria.
SAML (Security Assertion Markup Language) specifically uses XML formatted security assertions generated by an IdP to authorize user sessions at a Service Provider.
SAML is the standard open format for browser-based federated SSO utilizing XML payloads.

Anahtar Kavram

Federated Identity Architecture and Web Single Sign-On (SAML)
Tahmini Süre:1m 0s
Bu soruyu puanla