nerdexam
CompTIA

CAS-002 · Question #334

A company has migrated its data and application hosting to a cloud service provider (CSP). To meet its future needs, the company considers an IdP. Why might the company want to select an IdP that is…

The correct answer is A. A circle of trust can be formed with all domains authorized to delegate trust to an IdP D. Greater security can be provided if the circle of trust is formed within multiple CSP domains. Selecting an IdP separate from the CSP enables a broader federated circle of trust across multiple domains and improves security by distributing identity authority beyond a single vendor.

Technical Integration of Enterprise Components

Question

A company has migrated its data and application hosting to a cloud service provider (CSP). To meet its future needs, the company considers an IdP. Why might the company want to select an IdP that is separate from its CSP? (Select TWO).

Options

  • AA circle of trust can be formed with all domains authorized to delegate trust to an IdP
  • BIdentity verification can occur outside the circle of trust if specified or delegated
  • CReplication of data occurs between the CSP and IdP before a verification occurs
  • DGreater security can be provided if the circle of trust is formed within multiple CSP domains
  • EFaster connections can occur between the CSP and IdP without the use of SAML

How the community answered

(39 responses)
  • A
    64% (25)
  • B
    5% (2)
  • C
    21% (8)
  • E
    10% (4)

Why each option

Selecting an IdP separate from the CSP enables a broader federated circle of trust across multiple domains and improves security by distributing identity authority beyond a single vendor.

AA circle of trust can be formed with all domains authorized to delegate trust to an IdPCorrect

A separate IdP allows the organization to form a circle of trust that spans all authorized domains, enabling federated identity management across multiple cloud services and environments rather than being constrained to a single CSP's identity services.

BIdentity verification can occur outside the circle of trust if specified or delegated

Identity verification occurring outside the circle of trust is not a desired security outcome and does not represent an advantage of selecting a separate IdP - all trusted verification should remain within the defined circle of trust.

CReplication of data occurs between the CSP and IdP before a verification occurs

Data replication between the CSP and IdP prior to verification is not a standard behavior or recognized benefit of federated identity architecture and is not a valid reason to select a separate IdP.

DGreater security can be provided if the circle of trust is formed within multiple CSP domainsCorrect

Establishing the circle of trust across multiple CSP domains through an independent IdP improves security by eliminating a single vendor's control over all identity verification, reducing vendor lock-in and avoiding a single point of failure in the authentication chain.

EFaster connections can occur between the CSP and IdP without the use of SAML

SAML is the standard protocol used for federated authentication between an IdP and CSP; bypassing SAML is not an advantage, and connection speed is not a meaningful criterion for IdP selection in this context.

Concept tested: Federated identity provider selection and circle of trust architecture

Source: https://csrc.nist.gov/publications/detail/sp/800-63/3/final

Topics

#identity federation#IdP#circle of trust#cloud identity management

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice