CompTIA Security+ (SY0-701) · Free practice question 6 of 12
OAuth delegated authorization without passwords
A scheduling app built by Mossgiel Software needs to read users' calendars from a large email provider. Users should approve access without ever giving their email password to the app. Which standard is designed for this?
- A.LDAP
- B.RADIUS
- C.OAuth
- D.Kerberos
Show answer and explanation
Correct answer: C. OAuth
Why: OAuth lets a user authorize an application to access specific resources on their behalf using tokens, so the app never receives the user's password. RADIUS provides AAA for network access, and Kerberos issues tickets mainly within an enterprise domain. LDAP is a protocol for querying directory services.
More free CompTIA Security+ (SY0-701) questions
- Access control vestibule stops tailgating
- Trusted Platform Module characteristics
- Blockchain open public ledger integrity
- Virtual machine escape vulnerability
- Jump server for administrative access
- Non-disclosure agreement for consultants
- Passive reconnaissance from public sources
- Mean time between failures reliability
- Gap analysis against a framework
- Offline backups for ransomware recovery
- Steganography hiding data in images