CV0-003 · Question #301
A company has been migrating a significant number of its on-premises applications to various SaaS providers. The IT department has noticed the following: 1. User account management has become…
The correct answer is B. Multifactor authentication D. Password synchronization E. Federation. Managing identities across multiple SaaS providers while reducing account compromises and simplifying access is best addressed with MFA, password synchronization, and federation together.
Question
Options
- ASingle sign-on
- BMultifactor authentication
- CNetwork intrusion prevention system
- DPassword synchronization
- EFederation
- FIPSec tunnel to the SaaS providers
- GVPN to SaaS providers
How the community answered
(37 responses)- A3% (1)
- B73% (27)
- C8% (3)
- F3% (1)
- G14% (5)
Why each option
Managing identities across multiple SaaS providers while reducing account compromises and simplifying access is best addressed with MFA, password synchronization, and federation together.
Single sign-on is a narrower capability typically scoped within one organization's boundary, whereas federation is the more comprehensive cross-domain solution appropriate for external SaaS providers.
MFA directly addresses increased account compromises by requiring additional verification factors beyond passwords, significantly reducing the risk of credential-based attacks across dispersed SaaS platforms.
A network intrusion prevention system operates at the network layer to detect threats and does not address identity management, account compromise, or SaaS access challenges.
Password synchronization reduces the administrative burden of managing separate credentials per SaaS provider by keeping user passwords consistent across services, directly addressing the account management challenge.
Federation establishes trust relationships between the organization's identity provider and multiple SaaS providers, allowing users to authenticate via a single federated identity and access various SaaS applications - resolving both account management complexity and access difficulty.
IPSec tunnels to SaaS providers are architecturally impractical for public cloud SaaS services and do not address user account management or compromise issues.
VPN connections to SaaS providers add unnecessary complexity and do not solve user identity management or account security across multiple SaaS platforms.
Concept tested: Federation and MFA for multi-SaaS identity management
Source: https://learn.microsoft.com/en-us/azure/active-directory/hybrid/whatis-fed
Topics
Community Discussion
No community discussion yet for this question.