Courseiva
Security Architecture →mediumMultiple Choice

SY0-701 Federated identity Practice Question

A manufacturer wants partner-company users to access a procurement portal using their own company identities. The manufacturer does not want to create local accounts for each partner user, but it still needs to control what those users can do in the portal. Which approach should be used?

⚠ Common exam trap

Test-takers frequently confuse federation with synchronization, thinking that syncing user accounts into a local directory is the only way to control access, when in fact federation with role mapping provides both authentication delegation and authorization control without storing external user credentials.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use federated identity with role mapping so the portal trusts each partner’s identity provider.

Federated identity with role mapping allows the manufacturer to trust authentication performed by each partner's own identity provider (IdP) using standards like SAML 2.0 or OpenID Connect. This eliminates the need for local accounts while enabling fine-grained access control through roles or attributes passed in the assertion, ensuring partners can only perform authorized actions in the portal.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create one shared partner account for each external company and reuse the same password.

    Why it's wrong here

    A shared account with a reused password removes per-user attribution and cannot enforce granular per-user permissions, contradicting the requirement to control what each partner user does. It is tempting for its low administrative overhead, and would suit a kiosk or service account where individual accountability is not required.

  • ✓

    Use federated identity with role mapping so the portal trusts each partner’s identity provider.

    Why this is correct

    Federation lets external users authenticate with their own identity provider while the manufacturer still controls authorization inside the portal. Role mapping converts trusted identity assertions into specific portal permissions, which avoids local account sprawl and simplifies offboarding at the partner side.

  • ✗

    Synchronize every partner user into the manufacturer’s directory and require a separate password change.

    Why it's wrong here

    Synchronising partner identities into the manufacturer's directory creates the local accounts the scenario explicitly excludes, and forces partners to maintain separate credentials. It is tempting because directory synchronisation is standard for merging identity stores, and would be correct for subsidiaries or acquired companies under the same administrative control.

  • ✗

    Store partner passwords in the portal database and use password reset emails for access control.

    Why it's wrong here

    Storing partner passwords in the portal database makes the manufacturer a credential holder, defeating the goal of partners using their own company identities, and password reset emails are not an access-control mechanism. It is tempting as a self-service pattern, and would be correct for a consumer site with locally managed accounts.

About these practice questions

One of 1,030 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.