CAS-004 Security Engineering Practice Question
A company is implementing a privileged access management (PAM) solution to reduce the risk of standing privileges. Which feature allows users to request temporary elevated access for a specific task, which is automatically revoked after the task is completed?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Just-in-time (JIT) access provisioning
Just-in-time (JIT) access provisioning grants temporary privileges that expire after use, reducing standing privileges. Break-glass accounts are emergency accounts, not time-based.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Break-glass accounts
Why it's wrong here
Break-glass accounts are emergency standing credentials used when normal access paths fail; they are not requested per task and are not automatically revoked. It is tempting because they provide elevated access, but just-in-time privilege elevation with automatic expiry is the feature described.
- ✗
Password vaulting
Why it's wrong here
Password vaulting stores and checks out privileged credentials; it does not grant task-scoped, time-bound elevation that is automatically revoked. It is tempting because it removes standing credentials from users, but just-in-time access requests with automatic expiry are the feature that satisfies this requirement.
- ✗
Session recording
Why it's wrong here
Session recording captures activity for audit and forensic review; it neither grants nor revokes access. The stem requires just-in-time elevation with automatic expiry, which Microsoft Entra ID Privileged Identity Management provides through time-bound role activation. Recording sessions is the right control when the goal is accountability over already-granted privileged sessions.
- ✓
Just-in-time (JIT) access provisioning
Why this is correct
Just-in-time access provisioning grants elevated permissions only for the duration of a specific task, then automatically revokes them. This directly eliminates standing privileges, satisfying the stem's requirement that access be temporary and self-expiring. Microsoft Entra ID Privileged Identity Management implements this through time-bound role activation, with approvals and expiry enforced automatically.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.