Access Management: Federation and Password Complexity

Identity and Access Management (IAM)

During the onboarding process, an employee needs to create a password for an intranet account. The password must include ten characters, numbers, and letters, and two special characters. Once the password is created, the company will grant the employee access to other company-owned websites based on the intranet profile. Which of the following access management concepts is the company most likely using to safeguard intranet accounts and grant access to multiple sites based on a user's intranet account? (Choose two.)

  1. Federation Source Reference Answer
  2. Identity proofing
  3. Password complexity Source Reference Answer
  4. Default password changes
  5. Password manager

Community Votes

AC
100%

100% of anonymous learners picked answer AC. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests the ability to distinguish between internal single sign-on mechanisms (Federation) and external third-party authentication (OAuth), while recognizing basic security controls like Password Complexity.

This question tests the combination of password complexity requirements and identity federation to secure intranet accounts and grant cross-site access. The community consensus confirms that AC is the correct pair, highlighting federation's role in single sign-on across company systems.

Many candidates select 'Open Authentication' or 'OAuth' because they associate SSO with modern web standards, failing to recognize that 'Federation' is the broader, more appropriate term for establishing trust between organizational domains or internal resources managed by a central authority.

Community Discussion (6 comments)

dbrowndiver 👍 7 Selected: AC
"A". Federation and "C". are the correct answers. Federation facilitates access to multiple systems using a single intranet profile, and password complexity ensures that the passwords used are strong and secure. These concepts work together to safeguard intranet accounts and streamline user access across various company-owned websites.
TheMichael 👍 4 Selected: AC
Answer: A and C Federation establishes trust with a third-party that manages authentication, potentially providing a more secure solution for internal company systems. In this scenario the company is the third party that grants access to other company-owned websites. The answer is not Open authentication because Open authentication allows you to log into any other company-owned websites with your password, not intranet profile. Open authentication is less secure so a company would be less likely to use it in this fashion which also makes A and C make more sense.
NoobusAurelius 👍 2
I agree with NadirM_18 C and F makes sense because it only states Company owned websites, not company systems/apps.
NadirM_18 👍 1
Seems like this could be CF as this is within the same company.
c80f5c5 👍 3
This one is tricky because federation and open auth are very similar. I think OAuth might be for third party applications (like signing into a game with your facebook account) and not multiple company owned platforms like the question asks
35f7aac 👍 3
Hmm. Why not F instead of A? Question says "other company-owned websites". I thought Federation applies more to independent organizations connecting together.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The scenario describes two distinct security concepts. First, the requirement for 'ten characters, numbers, and letters, and two special characters' is a textbook definition of Password Complexity (C), which enforces strong credentials to prevent brute-force attacks. Second, granting access to multiple sites based on a single intranet profile is the core function of Federation (A). In enterprise contexts, federation allows a central identity provider to assert identity to multiple service providers (the other company-owned websites), enabling Single Sign-On (SSO) without sharing passwords directly between each site.

Why the Other Options Are Wrong

Default password changes (D) are not mentioned; the focus is on creation rules, not rotation. A password manager (E) is a tool used by users, not an architectural concept for granting access. Open Authentication (often referred to as OAuth or OIDC) is frequently confused here, but Option B 'Identity Proofing' refers to verifying the user's real-world identity during enrollment, not the ongoing access mechanism. While comments debate 'Open Auth,' Federation is the broader umbrella term often used in CompTIA Security+ for establishing trust relationships between domains, whereas OAuth is specifically an authorization framework, making A the stronger, more standard answer for this certification level.

Community Comment Notes

Comment [1] correctly identifies that Federation facilitates access using a single profile while Complexity ensures strength. Comment [4] raises a valid point about Federation usually implying independent organizations, but in the context of Security+, it applies to any trusted relationship between identity and service providers. Comment [3] correctly notes that OAuth is often for third-party app integration (like Facebook login), distinguishing it from internal corporate SSO solutions.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide