SSCP Access Controls Practice Question
A security consultant is reviewing an organization's identity and access management (IAM) architecture. The organization wants to implement a system where users can authenticate once and access multiple independent systems without re-entering credentials, while also enabling centralized session termination. Which TWO of the following are appropriate components or protocols to meet these requirements? (Choose two.)
⚠ Common exam trap
The trap here is assuming that OAuth 2.0 provides authentication, when it is actually an authorization framework; OpenID Connect is the authentication layer built on top of it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security Assertion Markup Language (SAML)
SAML and OpenID Connect are both federation protocols that enable single sign-on across independent systems. SAML uses XML assertions, while OIDC uses JSON Web Tokens and builds on OAuth 2.0. Both support centralized session management, allowing an identity provider to terminate sessions. OAuth 2.0 is for authorization, and RADIUS and LDAP are not designed for web-based SSO or centralized session termination.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Security Assertion Markup Language (SAML)
Why this is correct
SAML is an XML-based standard for exchanging authentication and authorization data between an identity provider and service providers. It enables single sign-on across independent systems and supports centralized session management through the identity provider. When a user authenticates once, SAML assertions can be used to access multiple service providers, and terminating the session at the identity provider can invalidate access.
- ✗
OAuth 2.0
Why it's wrong here
OAuth 2.0 is an authorization framework, not an authentication protocol. It allows third-party applications to obtain limited access to resources on behalf of a user, but it does not provide single sign-on or centralized session termination by itself. While OpenID Connect builds on OAuth 2.0 for authentication, OAuth 2.0 alone does not meet the stated requirements.
- ✗
Remote Authentication Dial-In User Service (RADIUS)
Why it's wrong here
RADIUS is a protocol for centralized authentication, authorization, and accounting for network access, such as VPN or Wi-Fi. It does not provide web-based single sign-on across independent systems or centralized session termination for web applications. While it can authenticate users, it lacks the federation and session management capabilities required here.
- ✗
Lightweight Directory Access Protocol (LDAP)
Why it's wrong here
LDAP is a directory access protocol used to query and modify directory services like Active Directory. It can store user credentials and attributes, but it does not inherently provide single sign-on across disparate systems or centralized session termination. LDAP is often used as a backend for authentication, but it is not a federation or SSO protocol itself.
- ✓
OpenID Connect (OIDC)
Why this is correct
OpenID Connect is an authentication layer built on top of OAuth 2.0. It provides single sign-on by allowing users to authenticate with an identity provider and obtain an ID token that can be used across multiple relying parties. It also supports session management, including the ability to log out from the identity provider and terminate sessions at participating applications.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.