Courseiva
Security Engineering →mediumMultiple Select

CAS-004 Security Engineering Practice Question

A company is implementing privileged access management (PAM) for its critical servers. Which THREE practices should be included to enhance security? (Select THREE.)

⚠ Common exam trap

CAS-005 often tests whether candidates can distinguish PAM-specific controls from general IAM hygiene — MFA and password rotation are commonly selected but are not the PAM practices the question targets.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Record and monitor all privileged sessions

Option A is correct because recording and monitoring all privileged sessions provides an audit trail and enables real-time detection of malicious or anomalous activity by administrators, which is a core PAM control. Option B is correct because just-in-time (JIT) access provisioning grants elevated privileges only when needed and for a limited time, reducing the standing attack surface and the window for credential misuse. Option C is correct because break-glass accounts provide controlled emergency access when normal PAM workflows fail, and when properly vaulted, monitored, and alerted on, they preserve availability without creating unmanaged privileged access. Option D is not the best fit because MFA for all users is a general identity control, not a PAM-specific practice for critical server privileged access. Option E is not correct because periodic password rotation for service accounts is a legacy practice that can weaken security and is not a core PAM enhancement compared to session monitoring, JIT access, and break-glass procedures.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Record and monitor all privileged sessions

    Why this is correct

    Session recording and monitoring create an auditable trail of every privileged action on critical servers, satisfying the PAM requirement for accountability and detecting misuse or insider threats in real time. This directly supports the scenario's goal of enhancing security for privileged access to critical infrastructure.

  • ✓

    Implement just-in-time (JIT) access provisioning

    Why this is correct

    Just-in-time provisioning grants elevated rights only for the approved window, then revokes them automatically, eliminating standing administrative privileges on critical servers. This directly satisfies the PAM requirement by shrinking the attack surface available to credential theft or misuse between legitimate administrative tasks.

  • ✓

    Use break-glass accounts for emergency access

    Why this is correct

    Break-glass accounts provide documented emergency access when normal PAM workflows fail, ensuring administrators are never locked out of critical servers. Vaulting credentials and alerting on use keeps this fallback auditable rather than becoming an unmonitored backdoor.

  • ✗

    Enforce multi-factor authentication for all users

    Why it's wrong here

    MFA for all users is baseline identity hygiene, not a PAM control for critical servers. It is tempting because MFA genuinely strengthens privileged sign-ins, but the scenario targets privileged access management specifically, where just-in-time elevation and session brokering apply. Applying MFA universally does not address standing privileged entitlements.

  • ✗

    Require periodic password rotation for all service accounts

    Why it's wrong here

    Periodic rotation of service account passwords creates operational risk and does not constrain standing privilege, which is the PAM objective. It is tempting because rotation is a long-standing credential hygiene practice, yet modern guidance favours vaulted, rotated secrets managed by the PAM platform rather than scheduled manual rotation across all service accounts.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.