ISC2 Certified Cloud Security Professional (CCSP) Practice Question
Your organization is moving several internal web and mobile applications to different public clouds. Security policy requires that users continue to authenticate with the on-premises corporate directory while the applications receive short-lived, signed tokens in JSON format. The solution must work with standard browser redirects and avoid synchronizing passwords to each provider. Which approach BEST satisfies these requirements?
Insert RADIUS proxy servers between the corporate network and each cloud tenant
Configure Kerberos cross-realm trusts with every public cloud provider
Publish the on-premises LDAP directory over VPN links to the cloud applications
Implement an Identity Provider that supports OpenID Connect using the OAuth 2.0 authorization-code flow
OpenID Connect (OIDC) extends OAuth 2.0 to provide federated authentication. During the authorization-code flow the user is redirected to the enterprise Identity Provider, which validates the corporate credentials and returns a signed JSON Web Token (ID Token) with a short lifetime. Cloud and SaaS applications consume this token without ever storing the user's password. RADIUS proxies and LDAP tunnels expose credentials rather than federating them, while Kerberos cross-realm trusts are not generally supported across disparate public cloud tenants.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is OpenID Connect and how does it extend OAuth 2.0?
Open an interactive chat with Bash
What is the OAuth 2.0 authorization-code flow?
Open an interactive chat with Bash
What is a JSON Web Token (JWT) and why is it used in authentication?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Application Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .