SY0-701 Federated identity Practice Question
A manufacturer wants partner-company users to access a procurement portal using their own company identities. The manufacturer does not want to create local accounts for each partner user, but it still needs to control what those users can do in the portal. Which approach should be used?
⚠ Common exam trap
Test-takers frequently confuse federation with synchronization, thinking that syncing user accounts into a local directory is the only way to control access, when in fact federation with role mapping provides both authentication delegation and authorization control without storing external user credentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use federated identity with role mapping so the portal trusts each partner’s identity provider.
Federated identity with role mapping allows the manufacturer to trust authentication performed by each partner's own identity provider (IdP) using standards like SAML 2.0 or OpenID Connect. This eliminates the need for local accounts while enabling fine-grained access control through roles or attributes passed in the assertion, ensuring partners can only perform authorized actions in the portal.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create one shared partner account for each external company and reuse the same password.
Why it's wrong here
A shared account with a reused password removes per-user attribution and cannot enforce granular per-user permissions, contradicting the requirement to control what each partner user does. It is tempting for its low administrative overhead, and would suit a kiosk or service account where individual accountability is not required.
- ✓
Use federated identity with role mapping so the portal trusts each partner’s identity provider.
Why this is correct
Federation lets external users authenticate with their own identity provider while the manufacturer still controls authorization inside the portal. Role mapping converts trusted identity assertions into specific portal permissions, which avoids local account sprawl and simplifies offboarding at the partner side.
- ✗
Synchronize every partner user into the manufacturer’s directory and require a separate password change.
Why it's wrong here
Synchronising partner identities into the manufacturer's directory creates the local accounts the scenario explicitly excludes, and forces partners to maintain separate credentials. It is tempting because directory synchronisation is standard for merging identity stores, and would be correct for subsidiaries or acquired companies under the same administrative control.
- ✗
Store partner passwords in the portal database and use password reset emails for access control.
Why it's wrong here
Storing partner passwords in the portal database makes the manufacturer a credential holder, defeating the goal of partners using their own company identities, and password reset emails are not an access-control mechanism. It is tempting as a self-service pattern, and would be correct for a consumer site with locally managed accounts.
Go deeper
Related to this question
Learn chapter
Cloud IAM and Identity Architecture
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
Key term
Identity
Identity is the unique set of attributes that defines a user, device, or service in a computer system, determining what they can access and do.
About these practice questions
One of 1,030 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.