CAS-004 Security Engineering Practice Question
An organization is deploying a just-in-time (JIT) privileged access management solution. What is a key benefit of JIT access compared to standing privileged accounts?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It reduces the window of exposure for privileged credentials.
JIT access provides temporary privileges that are automatically revoked after use, reducing the attack surface and limiting lateral movement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It allows users to permanently elevate privileges.
Why it's wrong here
That defeats the purpose of JIT.
- ✗
It eliminates the need for multi-factor authentication.
Why it's wrong here
JIT access narrows the window in which credentials exist; it does not remove authentication factors. MFA remains mandatory for privileged elevation, and JIT typically strengthens authentication requirements. Confusing reduced standing exposure with reduced authentication is the trap; MFA is the control that protects the elevation request itself.
- ✗
It requires no audit logging.
Why it's wrong here
JIT access generates detailed logs of every elevation, approval and session, which is central to privileged access governance. Removing audit logging would defeat accountability and violate compliance requirements. The temptation is that ephemeral accounts feel lower-risk, but ephemeral access increases the need for session recording and audit trails, not less.
- ✓
It reduces the window of exposure for privileged credentials.
Why this is correct
JIT provisioning grants privileged rights only for the approved duration, then revokes them automatically. This directly shrinks the attack surface created by standing accounts, whose credentials remain valid indefinitely. The reduced exposure window satisfies the scenario's core requirement: limiting how long compromised or misused privileged credentials stay exploitable.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.