Courseiva
mediumMultiple SelectObjective-mapped

CISSP Practice Question: Which THREE of the following are characteristics…

Which THREE of the following are characteristics of a federated identity management system?

⚠ Common exam trap

A common mix-up: candidates confuse federation with centralized SSO, assuming a single IdP or shared directory is required, when in fact federation decouples identity providers and directories across organizational boundaries.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

It relies on standard protocols such as SAML or OpenID Connect

Federated identity management systems rely on standard protocols like SAML (Security Assertion Markup Language) or OpenID Connect to exchange authentication and authorization data between identity providers (IdPs) and service providers (SPs). These protocols enable trust relationships across different security domains without requiring shared directories or a single IdP.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • It relies on standard protocols such as SAML or OpenID Connect

    Why this is correct

    Federated identity management fundamentally depends on established, open standards to facilitate secure and interoperable communication between distinct identity providers and service providers. Protocols like Security Assertion Markup Language (SAML) and OpenID Connect (OIDC) define the formats for exchanging authentication and authorization assertions, ensuring that diverse systems can understand and trust each other's identity information. This standardization is critical for enabling seamless cross-domain access and single sign-on without requiring proprietary integrations.

  • It operates with a single identity provider for all organizations

    Why it's wrong here

    Federated identity management is specifically designed to allow multiple, independent identity providers (IdPs) to participate within a trust framework, each managing its own user base. The core concept is to enable users authenticated by their respective organizational IdPs to access services from various service providers (SPs) without needing a central, universal IdP. Requiring a single identity provider would negate the distributed nature and primary benefit of federation, which is to bridge disparate identity systems.

  • It requires all participating organizations to use the same user directory

    Why it's wrong here

    A key advantage of federated identity management is its ability to operate across organizations that utilize diverse underlying user directories, such as Active Directory, LDAP, or cloud-based identity stores. Federation protocols abstract the specifics of user storage and authentication, focusing instead on the secure exchange of identity assertions. This means that participating entities do not need to standardize their internal directory infrastructure, promoting flexibility and reducing integration complexity.

  • It enables identity information to be shared across different security domains

    Why this is correct

    The fundamental objective of federated identity management is to securely and reliably share authenticated identity attributes and authorization decisions between distinct security domains or trust boundaries. This capability allows a user, once authenticated by their home organization's identity provider, to access resources hosted by a partner organization without re-authenticating. The sharing is governed by established trust relationships and cryptographic mechanisms, ensuring data integrity and confidentiality across disparate systems.

  • It provides single sign-on (SSO) across multiple organizations

    Why this is correct

    A primary benefit and characteristic of federated identity management is its provision of single sign-on (SSO) capabilities across multiple, independent organizations. Once a user authenticates with their home identity provider, they can seamlessly access various service providers within the federation without needing to re-enter credentials for each application. This significantly enhances user experience by reducing login fatigue and improves security by centralizing authentication points.

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.