ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your organization is building a cloud-hosted customer portal that must allow external business partners to reuse their own corporate credentials for seamless single sign-on. Each partner will continue to manage its user directory, and the portal must trust the partners' authentication assertions without storing partner passwords. Which secure architecture pattern best satisfies this requirement?
Implementing a security chain of responsibility across application components
Designing a three-tier defense-in-depth network segmentation model
Federated identity with a token-based single sign-on scheme (e.g., SAML or OpenID Connect)
Applying the Sherwood Applied Business Security Architecture (SABSA) framework
A federated identity pattern establishes trust relationships between distinct security domains so that an identity authenticated in one domain can be accepted in another. Using technologies such as SAML, OAuth, or OpenID Connect, the customer portal relies on identity providers operated by each partner to issue security tokens (assertions). This fulfills the need for single sign-on while letting partners retain control of their user stores and keeping passwords within the originating domain. SABSA is an enterprise security architecture framework, the security chain of responsibility focuses on accountability distribution inside a system, and an N-tier defense-in-depth model segments application layers rather than addressing cross-domain authentication.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is federated identity and how does it differ from traditional identity management?
Open an interactive chat with Bash
How do SAML, OAuth, and OpenID Connect compare for single sign-on use cases?
Open an interactive chat with Bash
Why is keeping passwords within the originating domain critical for security?
Open an interactive chat with Bash
What is Federated Identity?
Open an interactive chat with Bash
How does SAML differ from OAuth and OpenID Connect?
Open an interactive chat with Bash
Why does Federated Identity use tokens instead of storing partner passwords?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Architecture and Design
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .