問題文
A team is designing access control for an internal application and keeps treating authentication and authorization as one step. Why does the AAA framework keep them as separate functions?
選択肢
- Splitting them lets the system skip the second step for users who have already signed in once during the day, which is the main way the framework reduces the number of checks that have to be performed on every request that arrives.
- They are separated because only one of the two can be encrypted.
- Proving who someone is and deciding what that person may do answer different questions, so one identity can be granted different levels of access in different systems.
- They are separated so that the two functions can be handled by the same directory service, which is what makes a single sign-on experience possible.