During the onboarding process, an employee needs to create a password for an intranet account. The password must include ten characters, numbers, and letters, and two special characters. Once the password is created, the company will grant the employee access to other company-owned websites based on the intranet profile. Which of the following access management concepts is the company most likely using to safeguard intranet accounts and grant access to multiple sites based on a user's intranet account? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Federation, Password complexity.
Why this is the answer
The company is using password complexity by requiring a ten-character password with numbers, letters, and two special characters. This enforces a strong password policy. Federation is indicated because the company grants access to "other company-owned websites based on the intranet profile." This describes a federated identity management system where a single identity (the intranet account) is used to access multiple, independent systems. Identity proofing is the process of verifying a user's identity, not an access management concept for multiple sites. Default password changes are a security best practice but not directly described as being used here for granting access. A password manager is a tool, not an access management concept. Open authentication (OpenID Connect/OAuth) is a specific type of federation, but "federation" is the broader, more encompassing concept described.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed