CV0-004 Security Practice Question
An organization wants to ensure that only authenticated users from their corporate Active Directory can access cloud resources. Which federation protocol is most commonly used for this purpose?
⚠ Common exam trap
CV0-004 often tests the confusion between authentication and authorization protocols — candidates may pick OAuth 2.0 thinking it handles login, but OAuth is for delegated authorization, while SAML is the federation standard for SSO.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SAML
SAML (Security Assertion Markup Language) is the standard federation protocol used to enable single sign-on (SSO) between an identity provider (like Active Directory Federation Services) and a service provider (cloud resources). It exchanges authentication and authorization data in XML assertions, allowing users authenticated against corporate AD to access cloud applications without separate credentials. SAML is specifically designed for web-based federated identity scenarios, making it the most common choice for enterprise cloud SSO.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
LDAP
Why it's wrong here
LDAP is a directory access protocol, not a web federation protocol; it queries directory entries but does not issue the signed assertions cloud providers consume. It is tempting because Active Directory is LDAP-based, and LDAP would be correct for direct directory lookups rather than cross-domain single sign-on.
- ✗
OAuth 2.0
Why it's wrong here
OAuth 2.0 is an authorisation framework for delegated API access, issuing access tokens rather than authenticating users against a corporate directory. It is tempting because it underpins modern cloud sign-in flows, and would be correct for granting an application scoped access to a user's resources.
- ✗
RADIUS
Why it's wrong here
RADIUS authenticates network access for connections such as VPN or Wi-Fi, forwarding credentials to a server, but it does not produce federated tokens for cloud resource access. It is tempting because it centralises authentication against directory credentials, and would be correct for controlling dial-in or 802.1X access.
- ✓
SAML
Why this is correct
SAML exchanges signed assertions between the corporate identity provider and the cloud service, so Active Directory credentials authenticate users without replicating accounts. This satisfies the requirement that only authenticated corporate AD users reach cloud resources, unlike OAuth, which handles authorisation delegation rather than federated authentication.
Go deeper
Related to this question
About these practice questions
This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.