mediumMultiple Select
CISSP Practice Question: Which TWO are security benefits of using a…
Which TWO are security benefits of using a federated identity model?
⚠ Common exam trap
Candidates often confuse the benefits of federation. While federation centralizes authentication (which can create a single point of failure), its primary security benefit is that credentials are never shared with or stored by external service providers, thereby reducing the risk of credential theft.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Simplified user management across organizations
Option A (Simplified user management across organizations) is correct because federation lets each organization manage its own users in its own identity provider (IdP) while relying parties trust assertions via standards like SAML 2.0 or OpenID Connect, eliminating the need to duplicate accounts and provisioning across partner domains. Option D (Reduced risk of credential theft) is correct because users authenticate only to their home IdP and services receive tokens/assertions rather than reusable passwords, so credentials are not stored or transmitted to every relying party, shrinking the attack surface for credential harvesting. Option B is not marked correct because federation shifts trust to the IdP and does not inherently strengthen authentication strength; that requires MFA, certificate-based auth, or similar controls. Option C is wrong because password policies still apply at the IdP and are not eliminated by federation. Option E is wrong because federation is not inherently a single point of failure; well-designed deployments use multiple IdPs, failover, and fallback authentication to avoid that.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Simplified user management across organizations
Why this is correct
Federated identity centralizes user authentication at an Identity Provider (IdP), eliminating the need for each Service Provider (SP) to create and manage separate user accounts. This significantly reduces administrative overhead for account provisioning, de-provisioning, and password resets across multiple applications or organizations. Users benefit from a single sign-on experience, while administrators gain a consolidated view and control over user access, streamlining the entire identity lifecycle management process.
- ✗
Stronger authentication due to shared trust
Why it's wrong here
Federated identity enables Service Providers (SPs) to leverage the robust authentication mechanisms enforced by a trusted Identity Provider (IdP). An IdP can implement multi-factor authentication (MFA), biometrics, or other strong authentication methods, and the SP implicitly trusts the IdP's assertion that the user has been strongly authenticated. This allows SPs to benefit from enhanced security without needing to implement and manage these complex authentication systems themselves, thereby strengthening overall security posture.
- ✗
Elimination of password policies
Why it's wrong here
Federated identity does not eliminate the need for password policies; instead, it shifts the responsibility for enforcing them to the Identity Provider (IdP). The IdP, which manages the primary user credentials, must still implement and enforce strong password policies, such as complexity, length, and rotation requirements, to protect the foundational identity store. While Service Providers (SPs) may not directly manage user passwords, the security of the federated system critically depends on the IdP's adherence to robust credential management practices.
- ✓
Reduced risk of credential theft
Why this is correct
Federated identity does not inherently reduce the overall risk of credential theft; rather, it centralizes the point of attack for credentials. While Service Providers (SPs) do not store user passwords, the Identity Provider (IdP) remains a critical target for attackers seeking to compromise user credentials. A successful breach of the IdP could grant unauthorized access to all federated services, meaning the risk is concentrated rather than eliminated or broadly reduced across the ecosystem.
- ✗
Single point of failure for authentication
Why it's wrong here
Considering federated identity a benefit because it creates a single point of failure for authentication is incorrect; it is a significant disadvantage. If the central Identity Provider (IdP) experiences an outage or compromise, all Service Providers (SPs) relying on that IdP for authentication will become inaccessible, leading to widespread service disruption. This concentration of authentication responsibility means that the availability and resilience of the IdP are paramount to the entire federated ecosystem's operational continuity.
Go deeper
Related to this question
Learn chapter
Identity and Access Management (IAM)
Key term
SAML
Security Assertion Markup Language (SAML) is an open standard that allows one system to securely tell another system that a user is who they say they are, without sharing the user's password.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.