CAS-002 · Question #334
A company has migrated its data and application hosting to a cloud service provider (CSP). To meet its future needs, the company considers an IdP. Why might the company want to select an IdP that is…
The correct answer is A. A circle of trust can be formed with all domains authorized to delegate trust to an IdP D. Greater security can be provided if the circle of trust is formed within multiple CSP domains. Selecting an IdP separate from the CSP enables a broader federated circle of trust across multiple domains and improves security by distributing identity authority beyond a single vendor.
Question
A company has migrated its data and application hosting to a cloud service provider (CSP). To meet its future needs, the company considers an IdP. Why might the company want to select an IdP that is separate from its CSP? (Select TWO).
Options
- AA circle of trust can be formed with all domains authorized to delegate trust to an IdP
- BIdentity verification can occur outside the circle of trust if specified or delegated
- CReplication of data occurs between the CSP and IdP before a verification occurs
- DGreater security can be provided if the circle of trust is formed within multiple CSP domains
- EFaster connections can occur between the CSP and IdP without the use of SAML
How the community answered
(39 responses)- A64% (25)
- B5% (2)
- C21% (8)
- E10% (4)
Why each option
Selecting an IdP separate from the CSP enables a broader federated circle of trust across multiple domains and improves security by distributing identity authority beyond a single vendor.
A separate IdP allows the organization to form a circle of trust that spans all authorized domains, enabling federated identity management across multiple cloud services and environments rather than being constrained to a single CSP's identity services.
Identity verification occurring outside the circle of trust is not a desired security outcome and does not represent an advantage of selecting a separate IdP - all trusted verification should remain within the defined circle of trust.
Data replication between the CSP and IdP prior to verification is not a standard behavior or recognized benefit of federated identity architecture and is not a valid reason to select a separate IdP.
Establishing the circle of trust across multiple CSP domains through an independent IdP improves security by eliminating a single vendor's control over all identity verification, reducing vendor lock-in and avoiding a single point of failure in the authentication chain.
SAML is the standard protocol used for federated authentication between an IdP and CSP; bypassing SAML is not an advantage, and connection speed is not a meaningful criterion for IdP selection in this context.
Concept tested: Federated identity provider selection and circle of trust architecture
Source: https://csrc.nist.gov/publications/detail/sp/800-63/3/final
Topics
Community Discussion
No community discussion yet for this question.