An organization is implementing a federated identity system to allow employees to access a partner's cloud application using their corporate credentials. The solution must support single sign-on and use XML-based assertions. Which technology should be used?
SAML exchanges XML-based assertions between identity and service providers, enabling browser-based single sign-on across security domains. It directly satisfies the stem's requirement for federated authentication using corporate credentials at a partner's cloud application, with the identity provider issuing signed assertions the partner's application validates and trusts.
Why this answer
SAML (Security Assertion Markup Language) is an XML-based standard for exchanging authentication and authorization data between an identity provider and a service provider, enabling single sign-on. It is specifically designed for federated identity scenarios where users authenticate with their corporate credentials to access partner cloud applications. The requirement for XML-based assertions directly points to SAML.
Exam trap
The trap is confusing authentication with authorization: OAuth 2.0 is often mistakenly chosen for SSO, but it is an authorization framework, while SAML is the XML-based authentication standard for federated SSO.
How to eliminate wrong answers
Option A is wrong because Kerberos is a ticket-based authentication protocol used primarily within a Windows domain or trusted realm, not for cross-organizational federated SSO with XML assertions. Option C is wrong because OAuth 2.0 is an authorization framework for delegated access, not an authentication protocol, and it does not use XML assertions. Option D is wrong because OpenID Connect is an authentication layer built on OAuth 2.0 that uses JSON Web Tokens (JWT), not XML-based assertions.