Courseiva
Security ArchitecturemediumMultiple ChoiceObjective-mapped

SY0-701 Security Architecture Practice Question

A company uses four cloud applications and wants employees to sign in once with corporate credentials. The applications should trust the company’s identity platform, and disabling a user in the directory should remove access everywhere without separate password resets. Which architecture should the team implement?

⚠ Common exam trap

Many exam-takers confuse RADIUS (a network access protocol) with web SSO protocols like SAML or OpenID Connect, mistakenly thinking RADIUS can provide centralized web authentication and access revocation across cloud applications.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use federation with single sign-on through the corporate identity provider, such as SAML or OpenID Connect.

Federation with single sign-on (SSO) using the corporate identity provider (IdP) via SAML or OpenID Connect allows users to authenticate once with their corporate credentials. The cloud applications trust the IdP, so disabling a user in the corporate directory immediately revokes access across all applications without requiring separate password resets. This architecture decouples authentication from the applications and centralizes identity management.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create separate local accounts in each cloud application and synchronize passwords manually.

    Why it's wrong here

    Creating separate local accounts in each cloud application fragments identity management across four different directories. Manual password synchronization is error-prone, does not propagate lockout or termination status in real time, and leaves stale accounts that can be exploited. This approach prevents unified enforcement of corporate authentication policies such as MFA and fails to provide single sign-on because users must authenticate separately to every application.

  • Use federation with single sign-on through the corporate identity provider, such as SAML or OpenID Connect.

    Why this is correct

    Federation with SSO lets the company authenticate users centrally while each cloud application trusts assertions from the identity provider. That supports one login experience, faster deprovisioning, and consistent enforcement of corporate authentication controls across all apps.

  • Configure RADIUS authentication directly on each cloud application so users can reuse one password.

    Why it's wrong here

    RADIUS is commonly used for network access and some remote access workflows, but it is not the typical architecture for modern SaaS application federation. It also does not by itself provide the same broad SSO model described in the scenario.

  • Store one shared administrator password for all users in a password vault.

    Why it's wrong here

    A shared administrator password vault consolidates secrets but does not create per-user identities, so every person who retrieves the shared credential is indistinguishable from every other user. This violates least privilege and destroys non-repudiation, as audit logs cannot attribute specific actions to an individual. It also makes offboarding ineffective: removing one user's access to the vault does not invalidate the underlying password, and rotating it requires coordinated changes that still leave users sharing a single common secret.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on SY0-701

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Employees use one corporate login to sign in to email, the ticketing portal, and the HR application. After signing in once, the other apps accept the same identity without separate passwords. What capability is this?

easy
  • A.Single sign-on (SSO)
  • B.Federation
  • C.Multi-factor authentication (MFA)
  • D.Session timeout

Why A: Single sign-on (SSO) allows a user to authenticate once and gain access to multiple applications without re-entering credentials. In this scenario, the corporate login provides a token (e.g., Kerberos ticket or SAML assertion) that is accepted by the email, ticketing portal, and HR application, eliminating the need for separate passwords. This is the core capability of SSO.

Variation 2. Employees must sign in to several cloud applications with their corporate account, and terminated users should lose access without separate password resets in each app. What is the best solution?

easy
  • A.Create a separate local username and password in every cloud application.
  • B.Use federation with single sign-on from a central identity provider.
  • C.Store the same shared password in a password manager for all applications.
  • D.Allow each application to authenticate users only by device MAC address.

Why B: Federation with single sign-on (SSO) from a central identity provider (IdP) allows users to authenticate once using their corporate account, and the IdP issues security tokens (e.g., SAML assertions or OIDC tokens) that each cloud application trusts. When a user is terminated, the administrator disables the account in the IdP, and all applications immediately reject the user's tokens, eliminating the need for separate password resets in each app.

Variation 3. A company wants employees to use one corporate login for multiple SaaS applications, require MFA when users sign in from unmanaged devices, and centralize account lifecycle management. Which design best meets these requirements?

medium
  • A.Create separate local usernames and passwords in each SaaS application.
  • B.Use shared accounts for each department and keep one password vault for the team.
  • C.Implement federated single sign-on through a central identity provider with MFA and conditional access policies.
  • D.Require all users to connect through a VPN before any SaaS login and remove identity federation.

Why C: Federated single sign-on (SSO) through a central identity provider (IdP) like Azure AD or Okta allows employees to use one corporate login across multiple SaaS applications via protocols such as SAML 2.0 or OIDC. The IdP enforces MFA for unmanaged devices through conditional access policies (e.g., device compliance checks) and centralizes account lifecycle management by provisioning/deprovisioning users from a single directory (e.g., LDAP or SCIM).

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.