SY0-701 Single sign-on (SSO) Practice Question
Employees use one corporate login to sign in to email, the ticketing portal, and the HR application. After signing in once, the other apps accept the same identity without separate passwords. What capability is this?
⚠ Common exam trap
CompTIA often tests the distinction between SSO and federation, where candidates mistakenly choose federation because they think 'multiple apps' implies different domains, but the key is that federation involves separate organizations, not just separate applications within the same organization.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Single sign-on (SSO)
Single sign-on (SSO) allows a user to authenticate once and gain access to multiple applications without re-entering credentials. In this scenario, the corporate login provides a token (e.g., Kerberos ticket or SAML assertion) that is accepted by the email, ticketing portal, and HR application, eliminating the need for separate passwords. This is the core capability of SSO.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Single sign-on (SSO)
Why this is correct
Single sign-on lets one authentication event at a central identity provider, such as Microsoft Entra ID, issue a token that email, ticketing, and HR each trust, so no further passwords are requested. This directly satisfies the stem's constraint: one corporate login granting access across multiple applications after a single sign-in.
- ✗
Federation
Why it's wrong here
Federation links separate identity domains via trust, typically across organisations, so it does not describe one corporate login reused by internal apps. It is tempting because it also concerns shared identity, but the scenario is single sign-on within one domain, which federation is not required to achieve.
- ✗
Multi-factor authentication (MFA)
Why it's wrong here
MFA strengthens authentication by demanding a second factor; it does not share one identity across separate applications. It is tempting because both concern login security, but MFA answers how strongly a user proves identity, not how a single sign-on is reused across email, ticketing and HR.
- ✗
Session timeout
Why it's wrong here
Session timeout ends an authenticated session after inactivity; it does not propagate one login across multiple applications. It is tempting because both relate to session handling, but timeout governs when access expires, whereas the scenario describes one credential granting access to several apps without re-authentication.
Go deeper
Related to this question
Learn chapter
Cloud IAM and Identity Architecture
Key term
SSO
Single Sign-On (SSO) is an authentication process that allows a user to access multiple applications or systems with one set of login credentials.
Key term
Kerberos
Kerberos is a network authentication protocol that uses tickets and symmetric-key cryptography to verify the identity of users and services in a secure, non-repudiable way.
About these practice questions
One of 1,030 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.