exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 278 discussion

Actual exam question from CompTIA's SY0-601
Question #: 278
Topic #: 1
[All SY0-601 Questions]

An organization is migrating several SaaS applications that support SSO. The security manager wants to ensure the migration is completed securely. Which of the following application integration aspects should the organization consider before focusing into underlying implementation details? (Choose two.)

  • A. The back-end directory source
  • B. The identity federation protocol
  • C. The hashing method
  • D. The encryption method
  • E. The registration authority
  • F. The certificate authority
Show Suggested Answer Hide Answer
Suggested Answer: AB 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ronniehaang
Highly Voted 2 years, 6 months ago
Selected Answer: AB
The organization should consider the identity federation protocol and the back-end directory source before focusing into underlying implementation details during migration of several SaaS applications that support SSO. A. Identity Federation Protocol: The identity federation protocol helps in establishing trust between different organizations and systems for secure exchange of identity information between them. This helps to securely integrate multiple applications that support SSO and facilitates secure authentication of the users. B. Back-end Directory Source: A back-end directory source is used to store user identities and credentials and to perform authentication of the users. The organization needs to consider the integration of back-end directory sources of the SaaS applications with its existing infrastructure, to ensure secure and seamless migration of the SaaS applications.
upvoted 28 times
...
atrax
Highly Voted 2 years, 9 months ago
Selected Answer: BF
Certification covers both encryption and hashing
upvoted 20 times
Afel_Null
1 year, 10 months ago
If this is SaaS, then its not us that has to care about CA, it's the vendor.
upvoted 2 times
...
CS3000
1 year, 12 months ago
Correct me if I'm wrong, but wouldn't certificates be relevant to the implementation of the application? The question was focused on the prerequisites to implementation, such as ensuring the identities on the back-end are valid and the federation protocols are secured. Open to discussion!
upvoted 1 times
PropheticBettor
1 year, 9 months ago
They're not as relevant as the encryption method. These questions will include good answers but you want to choose the best. Certificate doesn't matter if encryption is nonexistent
upvoted 1 times
...
...
...
Murka
Most Recent 1 year ago
Selected Answer: AB
i think that answer is ab
upvoted 1 times
...
agfencer
1 year, 1 month ago
Selected Answer: BF
Identity federation protocol (B): Ensuring compatibility and security of the identity federation protocol is crucial. This protocol governs how authentication and authorization information are exchanged between the identity provider (IdP) and the service providers (SPs). Common protocols include SAML (Security Assertion Markup Language) and OAuth. Certificate authority (F): The organization should ensure that the certificates used for securing communications and verifying identities are issued by a trusted Certificate Authority (CA). This ensures the authenticity and integrity of SSO transactions and communications between the IdP and SPs.
upvoted 1 times
...
Shouqq_examtopics
1 year, 3 months ago
Selected Answer: AB
A) The back-end directory source and B) The identity federation protocol
upvoted 1 times
...
c56e966
1 year, 3 months ago
B. The identity federation protocol: Identity federation protocols such as SAML (Security Assertion Markup Language) or OAuth are crucial for enabling single sign-on (SSO) across multiple SaaS applications. Ensuring compatibility and proper configuration of the chosen federation protocol is essential for seamless and secure integration. F. The certificate authority: Certificates play a significant role in establishing trust and secure communication between systems. Ensuring that the certificates used for SSO and other authentication mechanisms are issued by a trusted certificate authority (CA) helps mitigate the risk of man-in-the-middle attacks and ensures the integrity of authentication processes.
upvoted 1 times
...
CaNe2o1
1 year, 6 months ago
Selected Answer: AB
Going with AB on this one.
upvoted 1 times
...
shaneo007
1 year, 7 months ago
A. Back-End Directory Source B. The identity federation protocol
upvoted 1 times
...
ganymede
1 year, 8 months ago
Selected Answer: AB
A. The back-end directory source B. The identity federation protocol
upvoted 1 times
...
Jackwasblk
1 year, 9 months ago
Selected Answer: AB
F is about websites.
upvoted 1 times
...
Teleco0997
1 year, 9 months ago
Selected Answer: BF
The encryption could be accurate in a general context of securing data, but the focus in the specific question (migration of SaaS applications supporting Single Sign-On (SSO)) is more focused on the identity and authentication aspects.
upvoted 1 times
...
ComPCertOn
1 year, 9 months ago
Selected Answer: BF
B and F make sense to me
upvoted 1 times
...
Afel_Null
1 year, 10 months ago
Selected Answer: BD
Federation interity, since SSO is emphasized. Encryption, because it's always used, and others make no sense: back-end directory, certificate authority - this is SaaS, we don't care about those, it's vendors job to ensure those. registration - we're not registering anything. hashing - there is no information that hashing is being used
upvoted 4 times
...
[Removed]
1 year, 10 months ago
Selected Answer: AB
I am going with AB, B is no issue here. I am thinking about A over F is because keyword they are talking about "migration" of SSO, you want to make the backend data source is compatible with whatever you are "migrating". F is also important but it is more of an "implementation" details, not "migration" related. You implement those DEF during development process. But in the context of migration, I will go with AB. Basically A is "where" you migrate to, and B is "how" you migrate.
upvoted 3 times
...
Abbey2
1 year, 11 months ago
Rely on ChatGPT suggestions at your peril!
upvoted 1 times
...
ApplebeesWaiter1122
2 years, 1 month ago
Selected Answer: BF
B. The identity federation protocol: The organization should consider the identity federation protocol used by the SaaS applications. This protocol determines how the SSO system communicates and exchanges authentication information with the applications. Ensuring compatibility between the identity federation protocol used by the SaaS applications and the organization's SSO infrastructure is crucial for successful and secure integration. F. The certificate authority: The organization should consider the certificate authority (CA) responsible for issuing digital certificates used for authentication and encryption purposes. The CA's reputation, reliability, and adherence to security best practices are important factors to consider. Trusting the CA ensures that the digital certificates used in the SaaS applications are valid, secure, and properly issued.
upvoted 6 times
...
justauser
2 years, 4 months ago
Selected Answer: BF
[GPT-4] Upon reviewing the question, you are correct. The answer should be B, F. Question #278: Answer: B, F. Explanation: The identity federation protocol and the certificate authority are the application integration aspects the organization should consider before focusing on underlying implementation details. The identity federation protocol, such as SAML or OAuth, enables secure authentication and single sign-on across multiple SaaS applications. The certificate authority (CA) plays a crucial role in ensuring the secure communication between the applications and the SSO system by issuing and managing digital certificates for secure data transmission.
upvoted 3 times
sarah2023
1 year, 11 months ago
In my experience chatGPT agrees to anything and everything as correct. You guys should really stop using it as a source for reference imo. Any time you ask it "are you sure?" , it changes its mind and replies in a way similar to what you've posted.
upvoted 11 times
Ayind3
1 year, 11 months ago
Really irritated when I see those "ChatGPT says" comments
upvoted 5 times
TreeeSon
1 year, 11 months ago
I used to use it, but sarah is correct. All it trakes sometimes is telling GPT "are you sure it isn't A" and it'll do a whole backpeddle and agree
upvoted 1 times
...
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...