CAS-004 Security Architecture Practice Question
A security architect for a healthcare provider must ensure that a new patient portal can exchange data with an external partner's system without the two organizations having to share or manage each other's identity credentials. The portal must support SAML assertions, provide centralized session revocation, and allow attribute-based authorization decisions at the relying party. Which of the following should the architect implement?
⚠ Common exam trap
The trap here is assuming that any trust relationship between organizations requires sharing or replicating credentials, when federation is specifically designed to avoid that.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy an identity federation gateway that consumes SAML assertions from the partner IdP and maps attributes to local authorization roles.
Federating identities through a gateway that consumes SAML assertions allows the portal to trust the partner's identity provider without exchanging credentials. Attributes carried in assertions can drive authorization decisions locally, and SAML single logout supports centralized session termination. The other approaches either require shared or duplicated credentials, lack SAML support, or expose internal directory services to an external party, none of which meet the stated interoperability and revocation requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the partner as a trusted certificate authority in the portal's internal PKI and issue client certificates to partner users.
Why it's wrong here
Mutual certificate authentication proves possession of a private key but does not convey user attributes, session state, or centralized revocation in the way the scenario requires. The portal would still need an external identity source to make attribute-based authorization decisions, and revoking a certificate does not terminate an active federated session. This approach also forces the partner to manage credentials inside the healthcare provider's PKI, which the scenario explicitly rules out.
- ✗
Publish the portal's user directory as an LDAP endpoint and require partner applications to bind directly against it during authentication.
Why it's wrong here
Exposing an internal directory over LDAP to external applications creates a broad attack surface and requires the partner to manage directory binds, which conflicts with the goal of not sharing credentials. LDAP bind does not carry SAML assertions, so the partner's existing identity provider cannot be leveraged. Attribute-based authorization would depend on directory schema rather than federated claims, and centralized session revocation across organizations is not provided.
- ✓
Deploy an identity federation gateway that consumes SAML assertions from the partner IdP and maps attributes to local authorization roles.
Why this is correct
An identity federation gateway lets the portal trust assertions from the partner's identity provider, so credentials never cross organizational boundaries. It consumes SAML assertions, maps attributes to local roles for attribute-based authorization, and can participate in centralized session revocation through SAML single logout. This directly satisfies the requirement to avoid shared credential management while supporting SAML and attribute-driven decisions at the relying party.
- ✗
Create duplicate local accounts for every partner user in the portal's directory and synchronize passwords on a nightly schedule.
Why it's wrong here
Provisioning duplicate local accounts means the portal stores and manages credentials for partner users, which is exactly the credential-sharing and lifecycle burden the scenario wants to eliminate. Nightly synchronization creates a window where revoked or changed partner accounts remain valid, undermining centralized revocation. It also provides no native SAML assertion handling and forces attribute mapping to be maintained manually rather than derived from authoritative partner attributes.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.