Courseiva
Security Architecture →mediumMultiple Choice

CAS-004 Security Architecture Practice Question

A security architect is reviewing the identity architecture for a company that uses a hybrid cloud. Employees authenticate to an on-premises Active Directory Domain Services (AD DS) domain and also need to access SaaS applications. The company wants to avoid storing separate passwords for each SaaS application and wants to enforce on-premises account status and group membership in real time. Which of the following should the architect implement?

⚠ Common exam trap

Candidates often confuse authentication protocols that sound similar, such as LDAP or RADIUS, with the SAML federation that SaaS applications actually use for browser-based single sign-on.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Federate the on-premises AD DS with each SaaS application using SAML 2.0, and configure the SaaS applications to trust the on-premises identity provider.

Federating on-premises AD DS with SAML 2.0 makes the domain the identity provider for SaaS applications. Users authenticate once with their AD credentials, and the SaaS application receives assertions about group membership and account status at each login. This satisfies the requirements for no separate passwords and real-time enforcement of on-premises account state, unlike cloud LDAP, local accounts, or RADIUS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy a standalone LDAP directory in the cloud and synchronize user passwords from AD DS using a one-way hash, then point each SaaS application to the cloud LDAP service.

    Why it's wrong here

    A standalone cloud LDAP directory with synchronized password hashes introduces a second identity store and does not guarantee real-time enforcement of on-premises account status. If an account is disabled on-premises, the synchronized hash may remain valid until the next sync cycle. Many SaaS applications do not support direct LDAP authentication, and password hash synchronization alone does not provide group-based authorization assertions.

  • ✗

    Configure each SaaS application with a separate local account for every employee, and use a password manager to generate and store unique passwords.

    Why it's wrong here

    Creating separate local accounts for each SaaS application defeats the goal of avoiding separate passwords and does not enforce on-premises account status or group membership. A password manager reduces the burden on users but does not integrate with AD DS, so disabling an on-premises account has no effect on the SaaS accounts. This approach also increases administrative overhead and the risk of orphaned accounts.

  • ✗

    Implement RADIUS authentication between the SaaS applications and the on-premises AD DS, and rely on RADIUS attributes to convey group membership.

    Why it's wrong here

    RADIUS is designed for network access authentication, not for federated web or SaaS application access. Most SaaS providers do not support RADIUS as an identity protocol for user login. RADIUS attributes can carry group information, but the protocol lacks the browser-based redirect and assertion flow needed for SaaS single sign-on, so it cannot enforce real-time AD DS account status for these applications.

  • ✓

    Federate the on-premises AD DS with each SaaS application using SAML 2.0, and configure the SaaS applications to trust the on-premises identity provider.

    Why this is correct

    Federating AD DS with SAML 2.0 allows the on-premises domain to act as the identity provider, so employees use their existing AD credentials and the SaaS application receives assertions about group membership and account status. This avoids separate passwords and enforces on-premises account state in real time because the identity provider evaluates the account at each authentication. It is the standard approach for hybrid identity with SaaS.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.