Courseiva
Security →mediumMultiple Choice

CV0-004 Security Practice Question

An organization wants to ensure that only authenticated users from their corporate Active Directory can access cloud resources. Which federation protocol is most commonly used for this purpose?

⚠ Common exam trap

CV0-004 often tests the confusion between authentication and authorization protocols — candidates may pick OAuth 2.0 thinking it handles login, but OAuth is for delegated authorization, while SAML is the federation standard for SSO.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SAML

SAML (Security Assertion Markup Language) is the standard federation protocol used to enable single sign-on (SSO) between an identity provider (like Active Directory Federation Services) and a service provider (cloud resources). It exchanges authentication and authorization data in XML assertions, allowing users authenticated against corporate AD to access cloud applications without separate credentials. SAML is specifically designed for web-based federated identity scenarios, making it the most common choice for enterprise cloud SSO.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    LDAP

    Why it's wrong here

    LDAP is a directory access protocol, not a web federation protocol; it queries directory entries but does not issue the signed assertions cloud providers consume. It is tempting because Active Directory is LDAP-based, and LDAP would be correct for direct directory lookups rather than cross-domain single sign-on.

  • ✗

    OAuth 2.0

    Why it's wrong here

    OAuth 2.0 is an authorisation framework for delegated API access, issuing access tokens rather than authenticating users against a corporate directory. It is tempting because it underpins modern cloud sign-in flows, and would be correct for granting an application scoped access to a user's resources.

  • ✗

    RADIUS

    Why it's wrong here

    RADIUS authenticates network access for connections such as VPN or Wi-Fi, forwarding credentials to a server, but it does not produce federated tokens for cloud resource access. It is tempting because it centralises authentication against directory credentials, and would be correct for controlling dial-in or 802.1X access.

  • ✓

    SAML

    Why this is correct

    SAML exchanges signed assertions between the corporate identity provider and the cloud service, so Active Directory credentials authenticate users without replicating accounts. This satisfies the requirement that only authenticated corporate AD users reach cloud resources, unlike OAuth, which handles authorisation delegation rather than federated authentication.

About these practice questions

This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.