A company is implementing an identity integration solution to connect their internal directory services with multiple third-party SaaS applications. The security team requires that all authentication traffic between their systems and external service providers must remain within their corporate network boundary. Which approach would BEST meet this requirement?
The correct answer is implementing a local identity proxy. A local identity proxy (sometimes called an identity broker or federation server) is installed within the corporate network and serves as an intermediary between the company's internal identity provider (directory services) and external service providers. This approach allows authentication traffic to be contained within the organization's network boundary because the proxy handles all external communications while maintaining internal connections to the identity store.
The token forwarding mechanism option is incorrect because security tokens are typically sent directly from identity provider to service provider, which would mean authentication traffic would cross network boundaries.
The cloud-based integration service would actually move authentication traffic outside the company's network boundary, which directly contradicts the requirement.
Implementing a credential caching system by itself doesn't necessarily keep authentication traffic within the network boundary - it may reduce the frequency of authentication events but doesn't control where that traffic flows when authentication does occur.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a local identity proxy?
Open an interactive chat with Bash
How does an identity proxy handle authentication traffic?
Open an interactive chat with Bash
Why is it important to keep authentication traffic within the corporate network?
Open an interactive chat with Bash
ISC2 CISSP
Identity and Access Management (IAM)
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
IT & Cybersecurity Package Join Premium for Full Access