Courseiva
hardMultiple Select

CISA Single Sign-On (SSO) Practice Question

Which THREE are core components of a comprehensive identity and access management (IAM) system? (Choose three.)

⚠ Common exam trap

ISACA often tests the distinction between infrastructure security tools (VPN, DLP) and core IAM functions (authentication, authorization, administration). The trap is confusing network-level or data-level controls with identity-centric components that directly manage user access rights and authentication workflows.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Single sign-on (SSO) for simplified authentication.

Single sign-on (SSO) is a core IAM component because it centralizes authentication so users log in once and gain access to multiple applications via federated protocols such as SAML 2.0 or OIDC, directly addressing authentication and access convenience. Privileged access management (PAM) is core IAM because it secures, vaults, and audits administrative and high-risk accounts (e.g., root, domain admin) with session recording, credential rotation, and just-in-time elevation. Role-based access control (RBAC) is core IAM because it is the authorization model that assigns permissions based on job roles, enforcing least privilege through role-to-permission mappings. A VPN is a network access/transport control, not an identity or access management function, and DLP is a data-centric security control for preventing exfiltration, so neither belongs to the core IAM component set.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Virtual private network (VPN) for remote network access.

    Why it's wrong here

    A VPN extends network access to remote users; it authenticates connections, not identities, and performs no provisioning, authorisation or entitlement management. It is tempting because remote access feels identity-adjacent, and would be correct when the requirement is encrypted tunnel access to internal resources rather than managing user identities and their access rights.

  • ✗

    Data loss prevention (DLP) to prevent data exfiltration.

    Why it's wrong here

    DLP inspects and blocks sensitive data leaving the organisation; it governs content flows, not who a user is or what they may access. It is tempting because both disciplines protect information, and would be correct when the requirement is preventing exfiltration of regulated data rather than authenticating users and managing their entitlements.

  • ✓

    Single sign-on (SSO) for simplified authentication.

    Why this is correct

    SSO lets users authenticate once and access multiple systems through a trusted identity provider, centralising credential verification. It is a core IAM component because it reduces password sprawl while preserving authentication assurance across federated applications.

  • ✓

    Privileged access management (PAM) for managing administrative accounts.

    Why this is correct

    PAM is a core IAM component because it controls, monitors and audits privileged administrative accounts, which standard authentication alone cannot govern. It satisfies the requirement for comprehensive coverage by addressing elevated-access risk that ordinary user provisioning and RBAC leave unmanaged.

  • ✓

    Role-based access control (RBAC) for assigning permissions based on job roles.

    Why this is correct

    RBAC is a core IAM component because it maps permissions to job roles rather than individuals, simplifying entitlement assignment and review. It satisfies the requirement for comprehensive IAM by providing the authorisation layer that determines what authenticated identities may access.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.