hardMultiple Select
CISA Single Sign-On (SSO) Practice Question
Which THREE are core components of a comprehensive identity and access management (IAM) system? (Choose three.)
⚠ Common exam trap
ISACA often tests the distinction between infrastructure security tools (VPN, DLP) and core IAM functions (authentication, authorization, administration). The trap is confusing network-level or data-level controls with identity-centric components that directly manage user access rights and authentication workflows.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Single sign-on (SSO) for simplified authentication.
Single sign-on (SSO) is a core IAM component because it centralizes authentication so users log in once and gain access to multiple applications via federated protocols such as SAML 2.0 or OIDC, directly addressing authentication and access convenience. Privileged access management (PAM) is core IAM because it secures, vaults, and audits administrative and high-risk accounts (e.g., root, domain admin) with session recording, credential rotation, and just-in-time elevation. Role-based access control (RBAC) is core IAM because it is the authorization model that assigns permissions based on job roles, enforcing least privilege through role-to-permission mappings. A VPN is a network access/transport control, not an identity or access management function, and DLP is a data-centric security control for preventing exfiltration, so neither belongs to the core IAM component set.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Virtual private network (VPN) for remote network access.
Why it's wrong here
A VPN extends network access to remote users; it authenticates connections, not identities, and performs no provisioning, authorisation or entitlement management. It is tempting because remote access feels identity-adjacent, and would be correct when the requirement is encrypted tunnel access to internal resources rather than managing user identities and their access rights.
- ✗
Data loss prevention (DLP) to prevent data exfiltration.
Why it's wrong here
DLP inspects and blocks sensitive data leaving the organisation; it governs content flows, not who a user is or what they may access. It is tempting because both disciplines protect information, and would be correct when the requirement is preventing exfiltration of regulated data rather than authenticating users and managing their entitlements.
- ✓
Single sign-on (SSO) for simplified authentication.
Why this is correct
SSO lets users authenticate once and access multiple systems through a trusted identity provider, centralising credential verification. It is a core IAM component because it reduces password sprawl while preserving authentication assurance across federated applications.
- ✓
Privileged access management (PAM) for managing administrative accounts.
Why this is correct
PAM is a core IAM component because it controls, monitors and audits privileged administrative accounts, which standard authentication alone cannot govern. It satisfies the requirement for comprehensive coverage by addressing elevated-access risk that ordinary user provisioning and RBAC leave unmanaged.
- ✓
Role-based access control (RBAC) for assigning permissions based on job roles.
Why this is correct
RBAC is a core IAM component because it maps permissions to job roles rather than individuals, simplifying entitlement assignment and review. It satisfies the requirement for comprehensive IAM by providing the authorisation layer that determines what authenticated identities may access.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.