SY0-701 exam dumps

SY0-701 practice question 355 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 355

Single answerInteroperability

A company is integrating a cloud-based identity provider with several third-party SaaS applications. The security team wants users to authenticate once with the corporate identity provider and then access the external applications without maintaining separate credentials for each service. The solution must work across different vendors' platforms and support federated authentication. Which technology is the BEST choice?

  1. A

    SAML

  2. B

    TACACS+

  3. C

    WPA3

  4. D

    Full disk encryption

Show answer and explanation

Correct answer: A

Explanation

The key requirement is interoperable federated authentication across different vendors' SaaS platforms with a single corporate login. SAML is the best fit because it is a widely adopted open standard for exchanging authentication and authorization data between an identity provider (IdP) and a service provider (SP). In real-world enterprise environments, SAML enables single sign-on without requiring each external application to maintain separate local credentials. This aligns with common identity federation best practices documented by major cloud and enterprise identity providers. TACACS+ is intended for device administration, WPA3 secures wireless access, and full disk encryption protects stored data rather than enabling authentication interoperability.

  • A. Correct.

    Correct. Security Assertion Markup Language (SAML) is an open standard commonly used for federated identity and single sign-on (SSO) between an identity provider and service providers across organizational and vendor boundaries. It is specifically designed to support interoperability for authentication and authorization assertions in web-based environments.

  • B. Incorrect.

    Incorrect. TACACS+ is a centralized authentication, authorization, and accounting protocol often used for administrative access to network devices such as routers and switches. It is not the best choice for federated web-based SSO across SaaS providers.

  • C. Incorrect.

    Incorrect. WPA3 is a wireless network security standard used to protect Wi-Fi communications. Although it improves wireless security, it does not provide federated identity or cross-platform single sign-on between cloud services.

  • D. Incorrect.

    Incorrect. Full disk encryption protects data at rest on storage devices. It does not address identity federation, interoperability between vendors, or SSO for SaaS applications.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam