N10-009 exam dumps

N10-009 practice question 248 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 248

Single answer

A company wants employees to use their existing corporate credentials to access a new cloud-based HR application without creating separate usernames and passwords. The security team also wants authentication to remain centralized with the company’s identity provider so user access can be disabled in one place when employees leave. Which solution best meets these requirements?

  1. A

    Deploy SAML-based single sign-on between the corporate identity provider and the HR application

  2. B

    Configure TACACS+ on the HR application so employees can authenticate with their network accounts

  3. C

    Use LDAP directly from the cloud HR application to authenticate users against the internal directory over the internet

  4. D

    Implement RADIUS between the identity provider and the HR application for web-based user authentication

Show answer and explanation

Correct answer: A

Explanation

The best answer is SAML-based single sign-on. SAML is an XML-based standard used to exchange authentication and authorization data between an identity provider and a service provider, making it a common solution for enterprise access to cloud applications. In this scenario, SAML allows the HR application to trust the company’s identity provider, so users authenticate with existing corporate credentials and do not need separate accounts at the SaaS provider. This also improves lifecycle management because access can be revoked centrally. By contrast, RADIUS is typically used for network access authentication, TACACS+ is designed mainly for administrative access to network devices, and LDAP is a directory protocol rather than a federated SSO protocol. These distinctions align with common industry guidance from vendors such as Microsoft, Okta, and Cisco, as well as the OASIS SAML standard documentation.

  • A. Correct.

    Correct. SAML is commonly used to provide federated authentication and single sign-on for web-based cloud applications. In this scenario, the organization can use its internal identity provider to authenticate users and send SAML assertions to the HR application. This allows users to sign in with existing corporate credentials while keeping authentication centralized. It also supports rapid deprovisioning because disabling the account in the identity provider can prevent access to connected applications.

  • B. Incorrect.

    Incorrect. TACACS+ is primarily used for centralized authentication, authorization, and accounting for administrative access to network devices such as routers and switches. It is not the standard choice for providing user single sign-on to a cloud-based HR web application. Someone might choose this option because TACACS+ is an AAA protocol, but its typical use case is device administration rather than federated web application access.

  • C. Incorrect.

    Incorrect. LDAP is a directory access protocol used to query and manage directory services, such as Active Directory. While some applications can use LDAP for authentication, directly exposing or relying on LDAP from a cloud SaaS application to an internal directory is generally not the best design for secure, scalable internet-facing SSO. It also does not inherently provide federated single sign-on in the same way SAML does. This option reflects a common misconception that directory access protocols are interchangeable with federation protocols.

  • D. Incorrect.

    Incorrect. RADIUS is commonly used for centralized AAA for network access scenarios such as VPN, wireless 802.1X, and dial-in access. It is not the standard protocol for browser-based single sign-on to cloud SaaS applications. A candidate might select RADIUS because it centralizes authentication, but the scenario specifically requires SSO for a web application, which is better addressed with SAML.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam