Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 8 discussion

Actual exam question from ISC's CISSP
Question #: 8
Topic #: 1
[All CISSP Questions]

Clothing retailer employees are provisioned with user accounts that provide access to resources at partner businesses. All partner businesses use common identity and access management (IAM) protocols and differing technologies. Under the Extended Identity principle, what is the process flow between partner businesses to allow this IAM action?

  • A. Clothing retailer acts as User Self Service, confirms identity of user using industry standards, then sends credentials to partner businesses that act as a Service Provider and allows access to services.
  • B. Clothing retailer acts as identity provider (IdP), confirms identity of user using industry standards, then sends credentials to partner businesses that act as a Service Provider and allows access to services.
  • C. Clothing retailer acts as Service Provider, confirms identity of user using industry standards, then sends credentials to partner businesses that act as an identity provider (IdP) and allows access to resources.
  • D. Clothing retailer acts as Access Control Provider, confirms access of user using industry standards, then sends credentials to partner businesses that act as a Service Provider and allows access to resources.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
franbarpro
Highly Voted 2 years, 2 months ago
Selected Answer: B
Agree with "B" - "Employees are provisioned with user accounts" sounds like the clothing retailer is an IdP. Also from crowdstrike: Identity and access management (IAM) is a framework that allows the IT team to control access to systems, networks and assets based on each user’s identity. IAM consists of two main components: 1. Identity management: Verifies the identity of the user based on existing information in an identity management database. 2. Access management: Uses the requestor’s identity to confirm their access rights to different systems, applications, data, devices and other resources. An IAM tool’s core functions are to: Assign a single digital identity to each user Authenticate the user Authorize appropriate access to relevant resources Monitor and manage identities to align with changes within the organization https://www.crowdstrike.com/cybersecurity-101/identity-access-management-iam/
upvoted 13 times
jackdryan
1 year, 7 months ago
B is correct
upvoted 1 times
...
...
gingasaurusrex
Highly Voted 1 year, 7 months ago
Selected Answer: B
B. Clothing retailer acts as identity provider (IdP), confirms identity of user using industry standards, then sends credentials to partner businesses that act as a Service Provider and allows access to services. The Extended Identity principle is a concept that is used to enable access to resources across partner businesses with different IAM technologies. In this scenario, the clothing retailer acts as an identity provider (IdP), which confirms the identity of the user using industry standards such as SAML, OAuth, or OpenID Connect. The IdP then sends the user's credentials to partner businesses that act as a Service Provider (SP) and allow access to resources. By using a common IAM protocol, such as SAML, OAuth, or OpenID Connect, the partner businesses can trust the clothing retailer's authentication of the user's identity and grant access to the requested resources. This allows the clothing retailer's employees to access resources at partner businesses without having to maintain separate user accounts for each partner business.
upvoted 5 times
...
Fouad777
Most Recent 1 week ago
B. Clothing retailer acts as identity provider (IdP), confirms identity of user using industry standards, then sends credentials to partner businesses that act as a Service Provider and allows access to services.
upvoted 1 times
...
[Removed]
3 months, 2 weeks ago
Selected Answer: B
B. Clothing retailer acts as identity provider (IdP), confirms identity, then sends credentials to partner businesses (Service Providers) for access.
upvoted 4 times
...
deeden
3 months, 3 weeks ago
Selected Answer: B
Agree with option B. Employees get their access from Clothing retailer (Idp) to access resources at partner businesses (Service provider).
upvoted 1 times
...
keithtemplin
6 months, 4 weeks ago
Selected Answer: C
The key here is that the clothing provider is providing resources. " that provide access to resources at partner businesses" A Service Provider is an application or service that users want to access, while an Identity Provider authenticates those users and validates their identities. The SP trusts the IdP to securely handle logins. There for the Retailer "Provides" resources becoming the "Service Provider"
upvoted 1 times
...
Ivanchun
1 year, 11 months ago
Selected Answer: B
Clothing retailer provide the identity
upvoted 1 times
...
Nickname53796
2 years, 1 month ago
Selected Answer: B
The SAML 2.0 specification utilizes three entities: the principal, the service provider, and the identity provider
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...