Courseiva
hardMultiple Choice

CV0-004 Practice Question: During a security audit, it is discovered that a…

During a security audit, it is discovered that a cloud application can be accessed using a shared service account that has elevated privileges. The audit recommends implementing a just-in-time (JIT) access model. What is the primary benefit of JIT access in this scenario?

⚠ Common exam trap

CV0-004 often tests the misconception that JIT 'eliminates' authentication or 'automates' auditing — the actual benefit is reducing persistent privileged access, so watch for answers that overstate what JIT does.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reduces the attack surface by minimizing persistent privileged access.

Just-in-time (JIT) access grants privileged permissions only for a limited, approved window and revokes them automatically afterward, rather than leaving standing elevated privileges in place. In this scenario, replacing the shared always-privileged service account with JIT access removes persistent high-privilege credentials that attackers could abuse, directly shrinking the attack surface. This is the core security benefit JIT is designed to deliver.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Automates auditing of third-party access.

    Why it's wrong here

    JIT access limits the duration of elevated privilege; it does not itself audit third-party access, which relies on logging and review tooling. It is tempting because JIT produces approval records, and would be correct if the audit finding concerned visibility into external parties rather than standing service-account privilege.

  • ✗

    Allows for easier management of user identities.

    Why it's wrong here

    JIT access grants privileged roles only for a bounded window, removing the standing elevated rights the shared account carries. Identity management simplification is a side effect, not the benefit. It would be the answer if the audit had flagged administrative overhead of provisioning accounts rather than persistent privilege exposure.

  • ✓

    Reduces the attack surface by minimizing persistent privileged access.

    Why this is correct

    JIT access grants privileged permissions only for a defined, approved window, then revokes them automatically. This eliminates the standing elevated privileges of the shared service account, directly shrinking the attack surface available to an attacker who compromises those credentials.

  • ✗

    Eliminates the need for user authentication.

    Why it's wrong here

    JIT access still requires authentication and adds approval and time-bound activation on top of it. It is tempting because activation feels frictionless, and would be correct only if the requirement were removing credential checks entirely, which no access model does.

About these practice questions

This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.