Courseiva
Security Engineering →mediumMultiple Choice

CAS-004 Security Engineering Practice Question

An organization is deploying a just-in-time (JIT) privileged access management solution. What is a key benefit of JIT access compared to standing privileged accounts?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It reduces the window of exposure for privileged credentials.

JIT access provides temporary privileges that are automatically revoked after use, reducing the attack surface and limiting lateral movement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It allows users to permanently elevate privileges.

    Why it's wrong here

    That defeats the purpose of JIT.

  • ✗

    It eliminates the need for multi-factor authentication.

    Why it's wrong here

    JIT access narrows the window in which credentials exist; it does not remove authentication factors. MFA remains mandatory for privileged elevation, and JIT typically strengthens authentication requirements. Confusing reduced standing exposure with reduced authentication is the trap; MFA is the control that protects the elevation request itself.

  • ✗

    It requires no audit logging.

    Why it's wrong here

    JIT access generates detailed logs of every elevation, approval and session, which is central to privileged access governance. Removing audit logging would defeat accountability and violate compliance requirements. The temptation is that ephemeral accounts feel lower-risk, but ephemeral access increases the need for session recording and audit trails, not less.

  • ✓

    It reduces the window of exposure for privileged credentials.

    Why this is correct

    JIT provisioning grants privileged rights only for the approved duration, then revokes them automatically. This directly shrinks the attack surface created by standing accounts, whose credentials remain valid indefinitely. The reduced exposure window satisfies the scenario's core requirement: limiting how long compromised or misused privileged credentials stay exploitable.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.