Implementing SAML for Cloud Vendor SSO
A company is implementing a vendor's security tool in the cloud. The security director does not want to manage users and passwords specific to this tool but would rather utilize the company's standard user directory. Which of the following should the company implement?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests knowledge of identity federation protocols, specifically distinguishing SAML's role in web-based SSO from network access protocols like RADIUS or 802.1X.
SAML is the correct protocol for exchanging authentication data between a cloud service and an enterprise directory to enable Single Sign-On (SSO). This page establishes that SAML allows users to use existing credentials for third-party tools.
Candidates often select RADIUS or CHAP because they are authentication protocols; however, these are typically used for network device access rather than web application identity federation with a central directory.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
SAML (Security Assertion Markup Language) is an open-standard XML-based framework specifically designed for exchanging authentication and authorization data between an identity provider (the company's directory) and a service provider (the vendor's cloud tool). By implementing SAML, the organization enables Single Sign-On (SSO), allowing users to authenticate once against their standard directory and gain access to the cloud application without managing separate passwords. This directly addresses the security director's requirement to avoid managing specific user accounts for the new tool.Why the Other Options Are Wrong
802.1X is a port-based network access control standard used to secure wired or wireless local area networks, not for web application identity federation. RADIUS is a networking protocol primarily used for remote access authentication, such as connecting to Wi-Fi or VPNs, rather than federating identities for cloud SaaS applications. CHAP is a simple challenge-response authentication protocol used within PPP connections, lacking the federation capabilities required to integrate with a standard user directory for web services.Community Comment Notes
The community consensus strongly favors SAML, with multiple comments highlighting its role in enabling SSO. As Benrosan noted, "SAML helps enable SSO," which aligns perfectly with the goal of using a standard directory. Other commenters correctly identified SAML as the standard for exchanging authentication data between parties, reinforcing the technical definition provided in official study guides.Exam Strategy
When a question mentions 'cloud,' 'vendor tool,' and 'standard user directory' together, think Identity Federation. SAML and OIDC are the primary protocols for this scenario. Reserve RADIUS and 802.1X for network infrastructure questions.
Frequently Asked Questions
Why is RADIUS incorrect for cloud vendor integration?
RADIUS is designed for network access authentication (like Wi-Fi or VPN), not for web application identity federation and Single Sign-On.
Does SAML require password management for the vendor tool?
No, SAML enables Single Sign-On, so users authenticate against their existing directory once and do not need separate passwords for the vendor tool.