Courseiva
Security →hardMultiple Choice

CV0-004 Security Practice Question

A company's cloud environment uses Microsoft Entra ID for identity management. They want to allow employees to sign in using their existing on-premises Active Directory credentials without synchronizing passwords to the cloud. Which federation protocol should they use?

⚠ Common exam trap

CV0-004 often tests the confusion between authentication protocols (Kerberos, LDAP) and federation protocols (SAML, WS-Federation, OpenID Connect), tricking candidates into picking Kerberos because it is the native AD protocol.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SAML 2.0

SAML 2.0 is the correct choice because it is a federation protocol designed for web-based single sign-on (SSO), allowing Microsoft Entra ID to trust authentication assertions issued by on-premises Active Directory Federation Services (AD FS) without replicating password hashes to the cloud. Microsoft Entra ID supports SAML 2.0 as a federated identity provider, so users authenticate on-premises and receive a signed token that Microsoft Entra ID accepts. This satisfies the requirement of using existing AD credentials without password synchronization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    LDAP

    Why it's wrong here

    LDAP is a directory access protocol, not a federated authentication protocol, so it cannot issue the tokens needed for cross-domain sign-in. It is tempting because it queries directory data, and would be correct for reading user attributes rather than federating identities.

  • ✗

    Kerberos

    Why it's wrong here

    Kerberos authenticates within a domain realm using ticket-granting services; it cannot federate on-premises Active Directory identities into Microsoft Entra ID without password synchronisation. It is tempting because Active Directory natively uses Kerberos, but it would be correct for internal domain authentication, not cross-realm cloud federation.

  • ✗

    OAuth 2.0

    Why it's wrong here

    OAuth 2.0 is an authorisation framework for delegated API access via tokens, not a protocol that federates on-premises Active Directory authentication into Microsoft Entra ID. It is tempting because it underpins modern sign-in flows, but it would be the right answer for granting an application scoped access to a resource, not for password-hash-free domain sign-in.

  • ✓

    SAML 2.0

    Why this is correct

    SAML 2.0 federates identity so Microsoft Entra ID trusts authentication assertions from on-premises Active Directory, letting employees sign in with existing credentials. This satisfies the stem's no-password-synchronisation constraint, unlike password hash synchronisation, which replicates credentials to the cloud.

About these practice questions

One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.