Courseiva
easyMultiple ChoiceObjective-mapped

CAS-004 Practice Question: A security architect is evaluating a new identity…

A security architect is evaluating a new identity management solution. The requirement is to allow users to authenticate using their existing social media accounts while maintaining corporate control over access policies. Which architecture best meets this requirement?

⚠ Common exam trap

The CAS-004 exam often tests the distinction between authentication and authorization, and the trap here is that candidates may confuse SSO with LDAP (Option B) as sufficient for external identity federation, failing to recognize that LDAP requires direct directory membership and does not support trust delegation to external IdPs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Federated identity management using Security Assertion Markup Language (SAML)

Federated identity management using SAML enables users to authenticate via external identity providers (e.g., social media platforms) while the corporate system retains control over access policies through the exchange of SAML assertions. This architecture decouples authentication from authorization, allowing the corporate service provider to enforce its own rules based on trusted identity claims.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Privileged access management (PAM) solution

    Why it's wrong here

    PAM manages admin accounts, not general user authentication.

  • Single sign-on (SSO) using a corporate LDAP directory

    Why it's wrong here

    SSO with LDAP requires corporate accounts, not social media.

  • Public Key Infrastructure (PKI) with digital signatures

    Why it's wrong here

    PKI provides non-repudiation but does not support social media authentication.

  • Federated identity management using Security Assertion Markup Language (SAML)

    Why this is correct

    Federation allows external IdPs like social media, while the enterprise controls policies.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.