ISC2 CISSP Practice Question

An international organization operates several SaaS applications hosted by different providers. The CIO wants employees to log in once at the start of the workday and then seamlessly access the expense portal, project tracker, and HR system without re-entering credentials. She also wants every provider to trust the corporate identity source. Which approach BEST satisfies this requirement?

  • Deploy separate local user databases in each SaaS application to keep credentials isolated.

  • Configure encrypted LDAP tunnels from each SaaS provider back to the on-prem directory but keep logins separate.

  • Require employees to maintain unique passwords for each system and store them in an enterprise password vault.

  • Implement federated identity management so the corporate IdP issues SAML or OIDC tokens accepted by all SaaS services.

ISC2 CISSP
Identity and Access Management (IAM)
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot