nerdexam
CompTIA

SK0-004 · Question #430

The purpose of Active Directory Federation Services (AD FS) is to:

The correct answer is B. complement authentication and access management features of AD DS. AD FS extends AD DS with federated identity and single sign-on capabilities, enabling authentication across organizational and application boundaries.

Server administration

Question

The purpose of Active Directory Federation Services (AD FS) is to:

Options

  • Areplace Active Directory Domain Services (AD DS) as a domain management tool in
  • Bcomplement authentication and access management features of AD DS
  • Ccomplement authentication and access management features of Active Directory Rights
  • Dreplace Active Directory Certificate Services (AD CS) in Windows Server 2013

How the community answered

(31 responses)
  • B
    94% (29)
  • C
    3% (1)
  • D
    3% (1)

Why each option

AD FS extends AD DS with federated identity and single sign-on capabilities, enabling authentication across organizational and application boundaries.

Areplace Active Directory Domain Services (AD DS) as a domain management tool in

AD FS does not replace AD DS - it depends on AD DS as the underlying identity store and extends its reach through federation rather than substituting its domain management functions.

Bcomplement authentication and access management features of AD DSCorrect

AD FS complements AD DS by adding claims-based authentication, federation trusts, and SSO features that AD DS alone does not provide. It works alongside AD DS to extend user authentication to external partners, cloud services, and web applications without replacing the core directory service.

Ccomplement authentication and access management features of Active Directory Rights

AD FS complements AD DS, not Active Directory Rights Management Services (AD RMS), which is a separate product focused on data protection and document-level access control.

Dreplace Active Directory Certificate Services (AD CS) in Windows Server 2013

AD FS does not replace AD CS, and Windows Server 2013 is not a valid Microsoft release, making this answer both technically and factually incorrect.

Concept tested: Active Directory Federation Services purpose and integration with AD DS

Source: https://learn.microsoft.com/en-us/windows-server/identity/active-directory-federation-services

Topics

#AD FS#federation services#authentication#access management

Community Discussion

No community discussion yet for this question.

Full SK0-004 Practice