Courseiva
mediumMultiple Select

CISSP Practice Question: Which TWO are security benefits of using a…

Which TWO are security benefits of using a federated identity model?

⚠ Common exam trap

Candidates often confuse the benefits of federation. While federation centralizes authentication (which can create a single point of failure), its primary security benefit is that credentials are never shared with or stored by external service providers, thereby reducing the risk of credential theft.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Simplified user management across organizations

Option A (Simplified user management across organizations) is correct because federation lets each organization manage its own users in its own identity provider (IdP) while relying parties trust assertions via standards like SAML 2.0 or OpenID Connect, eliminating the need to duplicate accounts and provisioning across partner domains. Option D (Reduced risk of credential theft) is correct because users authenticate only to their home IdP and services receive tokens/assertions rather than reusable passwords, so credentials are not stored or transmitted to every relying party, shrinking the attack surface for credential harvesting. Option B is not marked correct because federation shifts trust to the IdP and does not inherently strengthen authentication strength; that requires MFA, certificate-based auth, or similar controls. Option C is wrong because password policies still apply at the IdP and are not eliminated by federation. Option E is wrong because federation is not inherently a single point of failure; well-designed deployments use multiple IdPs, failover, and fallback authentication to avoid that.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Simplified user management across organizations

    Why this is correct

    Federated identity centralizes user authentication at an Identity Provider (IdP), eliminating the need for each Service Provider (SP) to create and manage separate user accounts. This significantly reduces administrative overhead for account provisioning, de-provisioning, and password resets across multiple applications or organizations. Users benefit from a single sign-on experience, while administrators gain a consolidated view and control over user access, streamlining the entire identity lifecycle management process.

  • ✗

    Stronger authentication due to shared trust

    Why it's wrong here

    Federated identity enables Service Providers (SPs) to leverage the robust authentication mechanisms enforced by a trusted Identity Provider (IdP). An IdP can implement multi-factor authentication (MFA), biometrics, or other strong authentication methods, and the SP implicitly trusts the IdP's assertion that the user has been strongly authenticated. This allows SPs to benefit from enhanced security without needing to implement and manage these complex authentication systems themselves, thereby strengthening overall security posture.

  • ✗

    Elimination of password policies

    Why it's wrong here

    Federated identity does not eliminate the need for password policies; instead, it shifts the responsibility for enforcing them to the Identity Provider (IdP). The IdP, which manages the primary user credentials, must still implement and enforce strong password policies, such as complexity, length, and rotation requirements, to protect the foundational identity store. While Service Providers (SPs) may not directly manage user passwords, the security of the federated system critically depends on the IdP's adherence to robust credential management practices.

  • ✓

    Reduced risk of credential theft

    Why this is correct

    Federated identity does not inherently reduce the overall risk of credential theft; rather, it centralizes the point of attack for credentials. While Service Providers (SPs) do not store user passwords, the Identity Provider (IdP) remains a critical target for attackers seeking to compromise user credentials. A successful breach of the IdP could grant unauthorized access to all federated services, meaning the risk is concentrated rather than eliminated or broadly reduced across the ecosystem.

  • ✗

    Single point of failure for authentication

    Why it's wrong here

    Considering federated identity a benefit because it creates a single point of failure for authentication is incorrect; it is a significant disadvantage. If the central Identity Provider (IdP) experiences an outage or compromise, all Service Providers (SPs) relying on that IdP for authentication will become inaccessible, leading to widespread service disruption. This concentration of authentication responsibility means that the availability and resilience of the IdP are paramount to the entire federated ecosystem's operational continuity.

About these practice questions

Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.