Access Management: Federation and Password Complexity
During the onboarding process, an employee needs to create a password for an intranet account. The password must include ten characters, numbers, and letters, and two special characters. Once the password is created, the company will grant the employee access to other company-owned websites based on the intranet profile. Which of the following access management concepts is the company most likely using to safeguard intranet accounts and grant access to multiple sites based on a user's intranet account? (Choose two.)
Community Votes
100% of anonymous learners picked answer AC. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests the ability to distinguish between internal single sign-on mechanisms (Federation) and external third-party authentication (OAuth), while recognizing basic security controls like Password Complexity.
This question tests the combination of password complexity requirements and identity federation to secure intranet accounts and grant cross-site access. The community consensus confirms that AC is the correct pair, highlighting federation's role in single sign-on across company systems.
Many candidates select 'Open Authentication' or 'OAuth' because they associate SSO with modern web standards, failing to recognize that 'Federation' is the broader, more appropriate term for establishing trust between organizational domains or internal resources managed by a central authority.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The scenario describes two distinct security concepts. First, the requirement for 'ten characters, numbers, and letters, and two special characters' is a textbook definition of Password Complexity (C), which enforces strong credentials to prevent brute-force attacks. Second, granting access to multiple sites based on a single intranet profile is the core function of Federation (A). In enterprise contexts, federation allows a central identity provider to assert identity to multiple service providers (the other company-owned websites), enabling Single Sign-On (SSO) without sharing passwords directly between each site.Why the Other Options Are Wrong
Default password changes (D) are not mentioned; the focus is on creation rules, not rotation. A password manager (E) is a tool used by users, not an architectural concept for granting access. Open Authentication (often referred to as OAuth or OIDC) is frequently confused here, but Option B 'Identity Proofing' refers to verifying the user's real-world identity during enrollment, not the ongoing access mechanism. While comments debate 'Open Auth,' Federation is the broader umbrella term often used in CompTIA Security+ for establishing trust relationships between domains, whereas OAuth is specifically an authorization framework, making A the stronger, more standard answer for this certification level.Community Comment Notes
Comment [1] correctly identifies that Federation facilitates access using a single profile while Complexity ensures strength. Comment [4] raises a valid point about Federation usually implying independent organizations, but in the context of Security+, it applies to any trusted relationship between identity and service providers. Comment [3] correctly notes that OAuth is often for third-party app integration (like Facebook login), distinguishing it from internal corporate SSO solutions.Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →