Courseiva

GSEC Windows Security Infrastructure Practice Question

An organization is deploying Just-In-Time (JIT) administration. Which Windows feature provides the necessary framework for creating temporary, elevated group memberships for domain administrators?

⚠ Common exam trap

Candidates often confuse PAM with 'Just Enough Administration' (JEA). While both are security frameworks, PAM is specific to managing time-bound administrative group memberships.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Privileged Access Management (PAM)

Privileged Access Management (PAM) using Microsoft Identity Manager (MIM) allows for the creation of shadow principals in a separate forest. This approach ensures that administrative rights are only granted for a specific window of time, drastically reducing the impact of a compromised account. This is a vital architectural pattern for securing Active Directory environments against persistent threats that rely on long-lived administrative privileges to maintain access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Restricted Groups GPO

    Why it's wrong here

    Restricted Groups allow administrators to define the membership of specific security groups. While this helps enforce static policy, it does not support temporary or time-bound memberships, failing the requirement for Just-In-Time access which requires dynamic removal of rights after a pre-determined expiration period.

  • ✓

    Privileged Access Management (PAM)

    Why this is correct

    PAM provides the capability to grant time-limited, Just-In-Time administrative access. By utilizing shadow principals and the MIM platform, organizations can provision temporary group memberships, ensuring that administrative accounts do not remain privileged indefinitely, which significantly mitigates the risk associated with account compromise.

  • ✗

    User Rights Assignment policy

    Why it's wrong here

    User Rights Assignment policies determine which security principals have specific rights, such as 'Log on as a service'. These are static assignments applied via Group Policy Objects and cannot be configured to expire or automatically revoke access, making them unsuitable for implementing JIT administration models.

  • ✗

    Group Policy Preferences

    Why it's wrong here

    Group Policy Preferences offer more flexibility than standard GPOs, including the ability to perform item-level targeting. However, they do not inherently support time-based revocation of group memberships or the automated workflow required for a secure JIT administrative model in a complex enterprise environment.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.