Courseiva
mediumMultiple Choice

200-201 Practice Question: A security administrator is implementing a…

A security administrator is implementing a privileged access management (PAM) solution. Which practice best enforces the principle of least privilege for administrators?

⚠ Common exam trap

Cisco often tests the misconception that monitoring or auditing alone satisfies least privilege, when in fact least privilege requires restricting access to the minimum necessary, not just observing it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Just-in-Time administration to grant temporary privileges

Just-in-Time (JIT) administration is the correct practice because it dynamically grants elevated privileges only for the duration of a specific task, then automatically revokes them. This directly enforces the principle of least privilege by ensuring administrators have no standing, permanent access beyond what is immediately needed. In contrast, shared accounts, permanent rights, or mere monitoring all leave excessive or uncontrolled privileges in place.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create shared admin accounts for the team

    Why it's wrong here

    Shared admin accounts remove individual attribution and prevent per-identity scoping, so least privilege cannot be enforced or audited. They are tempting for reducing licence costs or simplifying shift handovers, but the correct practice is unique named admin accounts with just-in-time role activation.

  • ✓

    Use Just-in-Time administration to grant temporary privileges

    Why this is correct

    Just-in-Time administration grants elevated rights only for a defined window, then revokes them automatically. This directly enforces least privilege by eliminating standing administrator access, so credentials are not permanently privileged. The temporary elevation satisfies the stem's requirement to minimise exposure whilst still permitting necessary administrative tasks.

  • ✗

    Grant permanent admin rights to all senior administrators

    Why it's wrong here

    Permanent rights for all senior administrators grant standing privileges far beyond each task, directly contradicting least privilege. It is tempting because it removes access-request friction for trusted staff, and it would be correct only where continuous unrestricted administrative access is genuinely required.

  • ✗

    Monitor admin activity without restricting access

    Why it's wrong here

    Monitoring alone records administrator actions without limiting their permissions, so standing privileges remain unrestricted. It is tempting because auditing supports accountability and detection, and it would be correct as a detective control complementing, rather than replacing, just-in-time privilege elevation.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.