Identity and Access Management Question #250

An organization is deploying a cloud-based Federated Identity solution to streamline collaboration with external partners. To mitigate the risk of a "domino effect" where a credential compromise at a partner organization leads to unauthorized access to internal corporate resources, which of the following is the most critical control to implement?

A. Enforcement of a 30-day password rotation policy for all federated accounts.
B. Mandatory Multi-Factor Authentication (MFA) for all federated identity assertions.
C. Implementation of internal network segmentation and micro-segmentation.
D. Deployment of advanced Endpoint Detection and Response (EDR) on partner devices.
Domain Concept: Identity and Access Management

This scenario evaluates management-level decision making in Identity and Access Management. In CISSP exam scenarios, evaluate answers through executive governance, risk assessment, life safety, and due diligence before implementing technical controls.

💡 View the Answer & Detailed Explanation

The correct answer to this scenario-based question requires an understanding of the CISSP Managerial Mindset. Register to view our in-depth explanation and access 1100+ adaptive questions completely free.

Fuel the Mission ☕

Keep the vault updated and the servers running.

$
Secure Payment via PayPal

Verified Excellence

Spread the Word

If you like us, share us with your peers.

Scroll to Top