Soru

Zorluk: ZorIdentity and Access Management Architecture

An enterprise security architecture team is evaluating modern Identity and Access Management (IAM) components to enhance security across hybrid environments. Based on enterprise security best practices, how should each IAM standard or architecture component be matched to its primary architectural role?

  • SCIM (System for Cross-domain Identity Management)Automating user account provisioning and deprovisioning across external SaaS applications
  • OAuth 2.0 Token ExchangePropagating delegated user context and security tokens securely across internal microservices
  • Privileged Access Management (PAM) with Ephemeral CredentialsEliminating static admin secrets by issuing short-lived dynamic credentials for system access
  • FIDO2 / WebAuthn FrameworkProviding phishing-resistant multi-factor authentication bound to hardware security keys

Cevap

Each IAM architectural component correctly aligns with its core functionality: SCIM handles automated identity provisioning, OAuth 2.0 Token Exchange propagates identity across microservices, PAM with ephemeral credentials eliminates static admin credentials, and FIDO2/WebAuthn delivers phishing-resistant authentication.
SCIM automates cross-domain provisioning; OAuth 2.0 Token Exchange securely transfers delegative identity context across API endpoints; PAM with ephemeral credentials removes persistent privileged secrets; and FIDO2/WebAuthn provides hardware-backed, domain-bound authentication resistant to phishing.

Adım Adım Çözüm

1
Analyze identity lifecycle standards
Identify SCIM as the standard protocol for automated provisioning and deprovisioning across SaaS services.
SCIM uses standardized RESTful schemas to sync user accounts between identity providers and cloud applications.
2
Evaluate token delegation in distributed systems
Identify OAuth 2.0 Token Exchange as the method for context propagation in microservice architecture.
Token exchange enables secure impersonation or delegation across backend services without exposing primary credentials.
3
Examine privileged access hardening techniques
Identify PAM with Ephemeral Credentials for dynamic short-lived administrative access.
Ephemeral credentials mitigate pass-the-hash and lateral movement risks associated with persistent admin accounts.
4
Assess strong authentication frameworks
Identify FIDO2/WebAuthn for hardware-bound, phishing-resistant authentication.
FIDO2 cryptographically binds authenticators to origin domains, preventing credential harvesting via proxy attacks.

Anahtar Kavram

Identity and Access Management Architecture Components and Protocols
Tahmini Süre:2m 0s
Bu soruyu puanla