nerdexam
CompTIA

CAS-003 · Question #335

A security architect is determining the best solution for a new project. The project is developing a new intranet with advanced authentication capabilities, SSO for users, and automated provisioning…

The correct answer is B. AD, certificate-based authentication, Kerberos, SPML. Kerberos allows for generic identity connector, and meets the SSO requirement.

Technical Integration of Enterprise Security

Question

A security architect is determining the best solution for a new project. The project is developing a new intranet with advanced authentication capabilities, SSO for users, and automated provisioning to streamline Day 1 access to systems. The security architect has identified the following requirements: 1. Information should be sourced from the trusted master data source. 2. There must be future requirements for identity proofing of devices and users. 3. A generic identity connector that can be reused must be developed. 4. The current project scope is for internally hosted applications only. Which of the following solution building blocks should the security architect use to BEST meet the requirements?

Options

  • ALDAP, multifactor authentication, oAuth, XACML
  • BAD, certificate-based authentication, Kerberos, SPML
  • CSAML, context-aware authentication, oAuth, WAYF
  • DNAC, radius, 802.1x, centralized active directory

How the community answered

(30 responses)
  • A
    3% (1)
  • B
    70% (21)
  • C
    10% (3)
  • D
    17% (5)

Explanation

Kerberos allows for generic identity connector, and meets the SSO requirement.

Topics

#identity management#SSO#Kerberos#SPML provisioning

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice