nerdexam
CompTIA

CAS-001 · Question #433

An organization is selecting a SaaS provider to replace its legacy, in house Customer Resource Management (CRM) application. Which of the following ensures the organization mitigates the risk of…

The correct answer is E. Ensure the SaaS provider supports directory services federation. The core risk identified is the burden and security exposure of managing a separate set of credentials for the SaaS CRM. Directory services federation (E) - using standards like SAML, OAuth, or OpenID Connect - allows the SaaS provider to trust the organization's existing…

Integration of Computing, Communications and Business Disciplines

Question

An organization is selecting a SaaS provider to replace its legacy, in house Customer Resource Management (CRM) application. Which of the following ensures the organization mitigates the risk of managing separate user credentials?

Options

  • AEnsure the SaaS provider supports dual factor authentication.
  • BEnsure the SaaS provider supports encrypted password transmission and storage.
  • CEnsure the SaaS provider supports secure hash file exchange.
  • DEnsure the SaaS provider supports role-based access control.
  • EEnsure the SaaS provider supports directory services federation.

How the community answered

(56 responses)
  • A
    16% (9)
  • B
    2% (1)
  • C
    7% (4)
  • D
    4% (2)
  • E
    71% (40)

Explanation

The core risk identified is the burden and security exposure of managing a separate set of credentials for the SaaS CRM. Directory services federation (E) - using standards like SAML, OAuth, or OpenID Connect - allows the SaaS provider to trust the organization's existing identity provider (e.g., Active Directory). Users authenticate once with their corporate credentials, and the federation passes an assertion to the SaaS platform. This eliminates separate passwords entirely. Dual factor authentication (A) and encrypted password transmission (B) improve security but still require separate credentials. Secure hash file exchange (C) is not a credential management solution. RBAC (D) manages authorization, not authentication credentials.

Topics

#identity federation#directory services#SaaS integration#credential management

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice