Courseiva
Access Controls →hardMultiple Select

SSCP Access Controls Practice Question

A security consultant is reviewing an organization's identity and access management (IAM) architecture. The organization wants to implement a system where users can authenticate once and access multiple independent systems without re-entering credentials, while also enabling centralized session termination. Which TWO of the following are appropriate components or protocols to meet these requirements? (Choose two.)

⚠ Common exam trap

The trap here is assuming that OAuth 2.0 provides authentication, when it is actually an authorization framework; OpenID Connect is the authentication layer built on top of it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security Assertion Markup Language (SAML)

SAML and OpenID Connect are both federation protocols that enable single sign-on across independent systems. SAML uses XML assertions, while OIDC uses JSON Web Tokens and builds on OAuth 2.0. Both support centralized session management, allowing an identity provider to terminate sessions. OAuth 2.0 is for authorization, and RADIUS and LDAP are not designed for web-based SSO or centralized session termination.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Security Assertion Markup Language (SAML)

    Why this is correct

    SAML is an XML-based standard for exchanging authentication and authorization data between an identity provider and service providers. It enables single sign-on across independent systems and supports centralized session management through the identity provider. When a user authenticates once, SAML assertions can be used to access multiple service providers, and terminating the session at the identity provider can invalidate access.

  • ✗

    OAuth 2.0

    Why it's wrong here

    OAuth 2.0 is an authorization framework, not an authentication protocol. It allows third-party applications to obtain limited access to resources on behalf of a user, but it does not provide single sign-on or centralized session termination by itself. While OpenID Connect builds on OAuth 2.0 for authentication, OAuth 2.0 alone does not meet the stated requirements.

  • ✗

    Remote Authentication Dial-In User Service (RADIUS)

    Why it's wrong here

    RADIUS is a protocol for centralized authentication, authorization, and accounting for network access, such as VPN or Wi-Fi. It does not provide web-based single sign-on across independent systems or centralized session termination for web applications. While it can authenticate users, it lacks the federation and session management capabilities required here.

  • ✗

    Lightweight Directory Access Protocol (LDAP)

    Why it's wrong here

    LDAP is a directory access protocol used to query and modify directory services like Active Directory. It can store user credentials and attributes, but it does not inherently provide single sign-on across disparate systems or centralized session termination. LDAP is often used as a backend for authentication, but it is not a federation or SSO protocol itself.

  • ✓

    OpenID Connect (OIDC)

    Why this is correct

    OpenID Connect is an authentication layer built on top of OAuth 2.0. It provides single sign-on by allowing users to authenticate with an identity provider and obtain an ID token that can be used across multiple relying parties. It also supports session management, including the ability to log out from the identity provider and terminate sessions at participating applications.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.