nerdexam
CompTIA

CV0-003 · Question #301

A company has been migrating a significant number of its on-premises applications to various SaaS providers. The IT department has noticed the following: 1. User account management has become…

The correct answer is B. Multifactor authentication D. Password synchronization E. Federation. Managing identities across multiple SaaS providers while reducing account compromises and simplifying access is best addressed with MFA, password synchronization, and federation together.

Security

Question

A company has been migrating a significant number of its on-premises applications to various SaaS providers. The IT department has noticed the following: 1. User account management has become challenging. 2. User account compromises have increased. 3. Accessing various SaaS applications is challenging. Which of the following should the IT security department implement to BEST resolve the issue? (Select THREE).

Options

  • ASingle sign-on
  • BMultifactor authentication
  • CNetwork intrusion prevention system
  • DPassword synchronization
  • EFederation
  • FIPSec tunnel to the SaaS providers
  • GVPN to SaaS providers

How the community answered

(37 responses)
  • A
    3% (1)
  • B
    73% (27)
  • C
    8% (3)
  • F
    3% (1)
  • G
    14% (5)

Why each option

Managing identities across multiple SaaS providers while reducing account compromises and simplifying access is best addressed with MFA, password synchronization, and federation together.

ASingle sign-on

Single sign-on is a narrower capability typically scoped within one organization's boundary, whereas federation is the more comprehensive cross-domain solution appropriate for external SaaS providers.

BMultifactor authenticationCorrect

MFA directly addresses increased account compromises by requiring additional verification factors beyond passwords, significantly reducing the risk of credential-based attacks across dispersed SaaS platforms.

CNetwork intrusion prevention system

A network intrusion prevention system operates at the network layer to detect threats and does not address identity management, account compromise, or SaaS access challenges.

DPassword synchronizationCorrect

Password synchronization reduces the administrative burden of managing separate credentials per SaaS provider by keeping user passwords consistent across services, directly addressing the account management challenge.

EFederationCorrect

Federation establishes trust relationships between the organization's identity provider and multiple SaaS providers, allowing users to authenticate via a single federated identity and access various SaaS applications - resolving both account management complexity and access difficulty.

FIPSec tunnel to the SaaS providers

IPSec tunnels to SaaS providers are architecturally impractical for public cloud SaaS services and do not address user account management or compromise issues.

GVPN to SaaS providers

VPN connections to SaaS providers add unnecessary complexity and do not solve user identity management or account security across multiple SaaS platforms.

Concept tested: Federation and MFA for multi-SaaS identity management

Source: https://learn.microsoft.com/en-us/azure/active-directory/hybrid/whatis-fed

Topics

#multifactor authentication#federation#password synchronization#SaaS identity management

Community Discussion

No community discussion yet for this question.

Full CV0-003 Practice