Courseiva
Security Architecture →easyMultiple Choice

SY0-701 Single sign-on (SSO) Practice Question

Employees use one corporate login to sign in to email, the ticketing portal, and the HR application. After signing in once, the other apps accept the same identity without separate passwords. What capability is this?

⚠ Common exam trap

CompTIA often tests the distinction between SSO and federation, where candidates mistakenly choose federation because they think 'multiple apps' implies different domains, but the key is that federation involves separate organizations, not just separate applications within the same organization.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Single sign-on (SSO)

Single sign-on (SSO) allows a user to authenticate once and gain access to multiple applications without re-entering credentials. In this scenario, the corporate login provides a token (e.g., Kerberos ticket or SAML assertion) that is accepted by the email, ticketing portal, and HR application, eliminating the need for separate passwords. This is the core capability of SSO.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Single sign-on (SSO)

    Why this is correct

    Single sign-on lets one authentication event at a central identity provider, such as Microsoft Entra ID, issue a token that email, ticketing, and HR each trust, so no further passwords are requested. This directly satisfies the stem's constraint: one corporate login granting access across multiple applications after a single sign-in.

  • ✗

    Federation

    Why it's wrong here

    Federation links separate identity domains via trust, typically across organisations, so it does not describe one corporate login reused by internal apps. It is tempting because it also concerns shared identity, but the scenario is single sign-on within one domain, which federation is not required to achieve.

  • ✗

    Multi-factor authentication (MFA)

    Why it's wrong here

    MFA strengthens authentication by demanding a second factor; it does not share one identity across separate applications. It is tempting because both concern login security, but MFA answers how strongly a user proves identity, not how a single sign-on is reused across email, ticketing and HR.

  • ✗

    Session timeout

    Why it's wrong here

    Session timeout ends an authenticated session after inactivity; it does not propagate one login across multiple applications. It is tempting because both relate to session handling, but timeout governs when access expires, whereas the scenario describes one credential granting access to several apps without re-authentication.

About these practice questions

One of 1,030 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.