Courseiva
Access Controls Concepts →mediumMultiple Choice

ISC2 CC Access Controls Concepts Practice Question

A software company uses a central identity provider so employees can sign in once and access email, the code repository, and the expense system without entering credentials again during the workday. The security team wants to describe the mechanism that lets the identity provider assert the user's identity to each application. Which technology is being used?

⚠ Common exam trap

The trap here is treating any single sign-on technology as interchangeable, when the identity provider asserting identity to separate applications specifically indicates federation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security Assertion Markup Language (SAML)

Federation allows one trusted identity provider to authenticate a user and send signed assertions to multiple service providers, delivering single sign-on across separate systems. SAML is the standard that defines these assertions and the request-response flow. The described environment, where one login grants access to email, code repository, and expense applications, is a textbook SAML federation deployment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Kerberos ticket granting

    Why it's wrong here

    Kerberos uses ticket-granting tickets within a realm, commonly in on-premises Windows environments. The scenario describes a central identity provider asserting identity to multiple cloud and internal applications, which is characteristic of federation protocols rather than Kerberos ticket exchange. While Kerberos also enables single sign-on, the described cross-application assertion by an identity provider points elsewhere.

  • ✗

    Remote Authentication Dial-In User Service (RADIUS)

    Why it's wrong here

    RADIUS centralizes authentication, authorization, and accounting for network access such as VPNs and Wi-Fi. It does not provide browser-based single sign-on assertions to business applications. The scenario involves a user accessing email and business systems after one login, which is federation, not network access control, so RADIUS does not apply.

  • ✓

    Security Assertion Markup Language (SAML)

    Why this is correct

    SAML is an XML-based federation standard where an identity provider sends signed assertions to service providers, enabling single sign-on. The scenario's central identity provider asserting identity to email, code repository, and expense applications matches SAML's identity provider and service provider model, making this the correct technology.

  • ✗

    Lightweight Directory Access Protocol (LDAP) bind

    Why it's wrong here

    LDAP binds authenticate users against a directory and can support simple sign-on within compatible applications, but it does not itself issue cross-domain assertions to independent service providers. The scenario describes an identity provider federating identity to multiple applications, which exceeds what a basic LDAP bind provides, so this option is not correct.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.