Identity and Authentication
Most identity questions come down to two things: what a factor actually proves, and which protocol does which job. SAML and OpenID Connect sign users in, OAuth grants an application access, Kerberos issues tickets inside a domain, and RADIUS and TACACS+ decide who may reach the network gear. The tables keep those apart.
Identity and Authentication · firsttry.app/cheatsheets/identity-and-authentication · original reference written from published exam objectives. Not affiliated with any certification body.
Authentication factors
| Factor | What it proves | Examples |
|---|---|---|
| Something you know | Knowledge | Password, PIN, passphrase |
| Something you have | Possession | Hardware token, smart card, authenticator app, passkey |
| Something you are | Inherence | Fingerprint, face, iris, voice |
| Somewhere you are | Location attribute | GPS, IP range, network |
| Something you do | Behavior attribute | Typing cadence, gait, signature dynamics |
Multifactor methods, strongest to weakest against phishing
| Method | Note |
|---|---|
| FIDO2 passkey or security key | Origin-bound, so a lookalike site gets nothing usable |
| Smart card with PIN | Certificate on the card, PIN unlocks it |
| Authenticator app, number matching | Push with a code the user must type from the sign-in screen |
| TOTP code | Time-based one-time password, six digits, 30-second window |
| Push approval without matching | Vulnerable to prompt fatigue |
| SMS or voice code | Vulnerable to SIM swap and interception |
Federation and single sign-on
| Protocol | Job | Token |
|---|---|---|
| SAML 2.0 | Browser SSO between an identity provider and a service provider | XML assertion |
| OAuth 2.0 | Delegated authorization: an app acts on a user's behalf | Access token (often JWT) |
| OpenID Connect | Authentication layered on OAuth 2.0 | ID token (JWT) |
| SCIM | Provisioning and deprovisioning accounts across systems | REST and JSON, not a token |
| WS-Federation | Older Microsoft federation, seen with AD FS | SAML token |
Directory and network authentication
| Protocol | Port | Job |
|---|---|---|
| Kerberos | 88 TCP/UDP | Ticket-based authentication inside a Windows domain |
| LDAP | 389 TCP | Directory queries and binds, plaintext |
| LDAPS | 636 TCP | LDAP over TLS |
| RADIUS | 1812 auth, 1813 accounting, UDP | Network access AAA; encrypts only the password |
| TACACS+ | 49 TCP | Device administration AAA; encrypts the whole payload, separates authorization |
| Diameter | 3868 TCP/SCTP | RADIUS successor used in carrier networks |
| 802.1X with EAP | Layer 2, no port | Port-based access control; supplicant, authenticator, authentication server |
Account and password controls
| Control | What it does |
|---|---|
| Least privilege | Grant only what the role needs, review it on a schedule |
| Just-in-time access | Elevate for a bounded window, then remove |
| Privileged access management | Vault, broker and record administrative sessions |
| Account lockout | Block after N failures for a period; slows online guessing |
| Password length over complexity | Current NIST guidance: long, screened against breach lists, no forced rotation |
| Conditional access | Allow, block or step up based on device, location, risk |
| Deprovisioning | Disable on the day access ends; orphaned accounts are the common finding |
Try it here
Three verified practice questions on this material. Answer one, and see the official page behind the answer.
4-1Security Operations
What is the minimum amount of entropy a session identifier should contain to resist brute-force guessing attacks?
Plan and automate identity governance
Who should be engaged to confirm that people still need access to a resource?
4-1Network Security
How wide is the source port field in a TCP header?
Five free questions on every practice exam. No account, no card.