nerdexam
CompTIA

CAS-001 · Question #524

Company XYZ provides cable television service to several regional areas. They are currently installing fiber-to-the-home in many areas with hopes of also providing telephone and Internet services…

The correct answer is C. The companies should federate, with the parent becoming the IdP, and the subsidiaries becoming. In a federated identity model, the Identity Provider (IdP) authenticates users and issues identity assertions, while Service Providers (SPs) consume those assertions to grant access. The parent company already has the existing customer relationship and billing data, making it…

Integration of Computing, Communications and Business Disciplines

Question

Company XYZ provides cable television service to several regional areas. They are currently installing fiber-to-the-home in many areas with hopes of also providing telephone and Internet services. The telephone and Internet services portions of the company will each be separate subsidiaries of the parent company. The board of directors wishes to keep the subsidiaries separate from the parent company. However all three companies must share customer data for the purposes of accounting, billing, and customer authentication. The solution must use open standards, and be simple and seamless for customers, while only sharing minimal data between the companies. Which of the following solutions is BEST suited for this scenario?

Options

  • AThe companies should federate, with the parent becoming the SP, and the subsidiaries becoming
  • BThe companies should federate, with the parent becoming the IdP, and the subsidiaries becoming
  • CThe companies should federate, with the parent becoming the IdP, and the subsidiaries becoming
  • DThe companies should federate, with the parent becoming the ASP, and the subsidiaries

How the community answered

(34 responses)
  • A
    9% (3)
  • B
    21% (7)
  • C
    68% (23)
  • D
    3% (1)

Explanation

In a federated identity model, the Identity Provider (IdP) authenticates users and issues identity assertions, while Service Providers (SPs) consume those assertions to grant access. The parent company already has the existing customer relationship and billing data, making it the natural IdP. The telephone and Internet subsidiaries are the services customers are trying to access, making them the SPs. This architecture satisfies all requirements: open standards (SAML/OAuth), minimal data sharing (the IdP asserts only what the SP needs), and seamless customer experience (single authentication). Option A reverses the roles incorrectly. Option B is similar but typically implies a different trust hierarchy. 'ASP' in option D is not a standard federation role. The correct answer has the parent as IdP and subsidiaries as SPs, matching SAML federation best practices.

Topics

#federation#IdP#SP#identity management

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice