Courseiva
Security Engineering →mediumMultiple Select

CAS-004 Security Engineering Practice Question

A security architect is designing a just-in-time (JIT) privileged access management (PAM) solution. Which TWO of the following are key characteristics of JIT access?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Access rights are automatically revoked after use or expiry.

Option B is correct because a defining property of JIT PAM is that elevated rights are time-bound and automatically revoked once the task completes or the approved window expires, eliminating lingering standing privileges. Option D is correct because JIT access grants privileges on-demand only when needed, for a limited duration, rather than provisioning them permanently in advance. Together, B and D capture the core JIT model: just-in-time, just-enough, and time-limited elevation. Option A is wrong because JIT privileges are temporary, not permanent, even if approval workflows are involved. Option C is wrong because break-glass accounts are an emergency fallback mechanism, not a defining characteristic of JIT access itself. Option E is wrong because standing privileges for routine tasks directly contradict the JIT principle of eliminating always-on access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Privileges are permanent but require approval each time.

    Why it's wrong here

    JIT access grants privileges only for a bounded window, then revokes them; permanent rights contradict that model regardless of approval. It is tempting because approval workflows do accompany PAM requests, so standing privileges with per-use approval sounds controlled, yet the defining mechanism is time-bound elevation, not persistent entitlement.

  • ✓

    Access rights are automatically revoked after use or expiry.

    Why this is correct

    Automatic revocation after use or expiry is fundamental to JIT: standing privileges are eliminated, so access exists only for the approved window. Once the task completes or the timer lapses, the entitlement is withdrawn without manual intervention, shrinking the attack surface.

  • ✗

    Break-glass accounts are used for emergency access.

    Why it's wrong here

    Break-glass accounts are a separate emergency fallback, not a characteristic of JIT elevation itself; they exist precisely because JIT approval paths can fail. It is tempting because both concepts appear in privileged access programmes, but JIT is defined by on-demand, time-bound activation, whereas break-glass accounts are pre-provisioned and used when normal JIT flows are unavailable.

  • ✓

    Privileges are granted on-demand for a limited time period.

    Why this is correct

    On-demand, time-bound elevation is the defining property of JIT access. Privileges are not permanently assigned; they are requested, approved and granted for a defined period, satisfying least privilege by limiting how long elevated rights remain usable.

  • ✗

    Users have standing privileges for routine tasks.

    Why it's wrong here

    Standing privileges for routine tasks are the opposite of JIT, which eliminates always-on rights and elevates only when needed. It is tempting because routine administrative duties must still be performed, and permanent roles appear to guarantee availability, but JIT instead provisions time-limited access per request, removing standing entitlement entirely.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.