Soru

Zorluk: OrtaIdentity and Access Management Architecture

Match each enterprise identity and access management (IAM) architectural component on the left to its primary functional responsibility on the right.

  • SAML Assertion Consumer Service (ACS)Receives and validates signed XML authentication assertions from an external Identity Provider during web-based federated single sign-on.
  • OAuth 2.0 Authorization ServerAuthenticates resource owners and issues scoped access tokens to client applications without exposing credentials.
  • SCIM Provisioning ServiceAutomates identity account creation, modification, and de-provisioning across heterogeneous enterprise systems using RESTful API payloads.
  • Kerberos Key Distribution Center (KDC)Grants Ticket Granting Tickets (TGT) and service tickets to authenticate users within an internal domain environment.

Cevap

SAML Assertion Consumer Service (ACS) matches receiving and validating signed XML assertions from an external IdP; OAuth 2.0 Authorization Server matches authenticating resource owners and issuing scoped access tokens; SCIM Provisioning Service matches automating identity account creation and de-provisioning via RESTful APIs; Kerberos Key Distribution Center (KDC) matches granting Ticket Granting Tickets and service tickets for internal domain authentication.
Each IAM component performs a specific architectural role in identity lifecycle management, federated web single sign-on, API authorization delegation, or local domain ticket authentication.

Adım Adım Çözüm

1
Identify SAML Assertion Consumer Service (ACS) function
Matches XML assertion processing at the Service Provider endpoint during federated SSO.
SAML reliance on XML signatures and HTTP posts to the ACS endpoint is characteristic of web-based SP-initiated or IdP-initiated federation.
2
Identify OAuth 2.0 Authorization Server function
Matches issuing scoped tokens for API authorization access.
OAuth 2.0 delegates authority through token issuance without sharing credentials with the client application.
3
Identify SCIM Provisioning Service function
Matches automated lifecycle management across external application identity stores.
SCIM defines schema models and HTTP operations for syncing user identity lifecycles.
4
Identify Kerberos Key Distribution Center (KDC) function
Matches issuing Ticket Granting Tickets (TGT) within a local Active Directory domain.
Kerberos relies on a trusted KDC to grant ticket-based mutual authentication on internal networks.

Anahtar Kavram

Enterprise IAM Architecture Components and Protocols
Bu soruyu puanla