mediummultiple choiceObjective-mapped

A SaaS vendor supports both browser access and a mobile app. The company wants employees to sign in with corporate credentials, avoid separate passwords for each app, and use token-based authentication that works well with modern APIs. Which integration should the architect choose?

Question 1mediummultiple choice
Full question →

A SaaS vendor supports both browser access and a mobile app. The company wants employees to sign in with corporate credentials, avoid separate passwords for each app, and use token-based authentication that works well with modern APIs. Which integration should the architect choose?

Answer choices

Why each option matters

Good practice is not just finding the correct option. The wrong answers often show the exact trap the exam wants you to fall into.

A

Distractor review

SAML federation to the SaaS vendor using browser assertions only.

SAML is common for browser sign-in, but it is less aligned with modern API and mobile token flows.

B

Best answer

OpenID Connect federation with the corporate identity provider.

OpenID Connect is built on modern token-based authentication and works well for browser, mobile, and API-driven applications.

C

Distractor review

LDAP bind authentication directly against each SaaS application.

LDAP is not a modern SaaS federation method and would create separate authentication paths for each application.

D

Distractor review

Kerberos tickets issued directly by the SaaS vendor.

Kerberos is typically used in internal domain environments and is not the usual choice for external SaaS federation.

Common exam trap

Common exam trap: answer the scenario, not the keyword

Many certification questions include familiar terms but test a specific constraint. Read the exact wording before choosing an answer that is generally true but wrong for this case.

Technical deep dive

How to think about this question

This question should be treated as a scenario, not a definition check. Identify the problem, the constraint and the best action. Then compare each option against those facts.

KKey Concepts to Remember

  • Read the scenario before looking for a memorised answer.
  • Find the constraint that changes the correct option.
  • Eliminate answers that are true in general but not in this case.
  • Use explanations to understand the rule behind the answer.

TExam Day Tips

  • Underline the problem statement mentally.
  • Watch for words such as best, first, most likely and least administrative effort.
  • Review why wrong options are wrong, not only why the correct option is correct.

Related practice questions

Related SY0-701 practice-question pages

Use these pages to review the topic behind this question. This is how one missed question becomes focused revision.

More questions from this exam

Keep practising from the same exam bank, or move into a focused topic page if this question exposed a weak area.

FAQ

Questions learners often ask

What does this SY0-701 question test?

Read the scenario before looking for a memorised answer.

What is the correct answer to this question?

The correct answer is: OpenID Connect federation with the corporate identity provider. — OpenID Connect is the best choice because it provides federation through the corporate identity provider while supporting modern, token-based authentication. It is well suited to both browser sessions and mobile or API-centric use cases. That means the company can centralize sign-in, reduce password sprawl, and still integrate cleanly with contemporary SaaS platforms. For Security+, recognizing when a modern token protocol is preferable to older directory-style authentication is an important architecture skill. Why others are wrong: SAML is useful for browser-based single sign-on, but it is less flexible for mobile and API workflows. LDAP binds are direct authentication connections, not a federated SaaS architecture. Kerberos is strong inside controlled Windows environments, but it is not normally used as the external federation method for third-party SaaS applications.

What should I do if I get this SY0-701 question wrong?

Then try more questions from the same exam bank and focus on understanding why the wrong options are tempting.

Discussion

Loading comments…

Sign in to join the discussion.