GSEC Windows Security Infrastructure Practice Question
An organization is deploying Just-In-Time (JIT) administration. Which Windows feature provides the necessary framework for creating temporary, elevated group memberships for domain administrators?
⚠ Common exam trap
Candidates often confuse PAM with 'Just Enough Administration' (JEA). While both are security frameworks, PAM is specific to managing time-bound administrative group memberships.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Privileged Access Management (PAM)
Privileged Access Management (PAM) using Microsoft Identity Manager (MIM) allows for the creation of shadow principals in a separate forest. This approach ensures that administrative rights are only granted for a specific window of time, drastically reducing the impact of a compromised account. This is a vital architectural pattern for securing Active Directory environments against persistent threats that rely on long-lived administrative privileges to maintain access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Restricted Groups GPO
Why it's wrong here
Restricted Groups allow administrators to define the membership of specific security groups. While this helps enforce static policy, it does not support temporary or time-bound memberships, failing the requirement for Just-In-Time access which requires dynamic removal of rights after a pre-determined expiration period.
- ✓
Privileged Access Management (PAM)
Why this is correct
PAM provides the capability to grant time-limited, Just-In-Time administrative access. By utilizing shadow principals and the MIM platform, organizations can provision temporary group memberships, ensuring that administrative accounts do not remain privileged indefinitely, which significantly mitigates the risk associated with account compromise.
- ✗
User Rights Assignment policy
Why it's wrong here
User Rights Assignment policies determine which security principals have specific rights, such as 'Log on as a service'. These are static assignments applied via Group Policy Objects and cannot be configured to expire or automatically revoke access, making them unsuitable for implementing JIT administration models.
- ✗
Group Policy Preferences
Why it's wrong here
Group Policy Preferences offer more flexibility than standard GPOs, including the ability to perform item-level targeting. However, they do not inherently support time-based revocation of group memberships or the automated workflow required for a secure JIT administrative model in a complex enterprise environment.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.