Courseiva

CRISC Information Technology and Security Practice Question

A risk practitioner is reviewing the organization's identity and access management (IAM) controls. The identity team proposes implementing just-in-time (JIT) privileged access with automated approval workflows and session recording. Which risk is MOST effectively mitigated by this approach compared to standing privileged accounts?

⚠ Common exam trap

Candidates often confuse the reduction of standing privileges with broader identity threats like credential stuffing, which JIT access does not address.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The risk that unused or stale privileged accounts accumulate and are exploited by attackers or insiders.

Standing privileged accounts are a persistent target because they remain valid even when unused. Just-in-time provisioning eliminates standing entitlements, granting elevated rights only for an approved, time-bound session. This shrinks the attack surface, removes dormant accounts that attackers and insiders could exploit, and adds approval and recording as compensating detective controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The risk of a denial-of-service attack saturating the network perimeter during peak business hours.

    Why it's wrong here

    Denial-of-service attacks consume network or application resources and are unrelated to how privileged entitlements are provisioned. JIT access changes the lifecycle of privileged credentials, not the capacity or resilience of the perimeter. Mitigating DoS requires traffic scrubbing, rate limiting, and redundancy, which are outside the scope of identity governance.

  • ✗

    The risk that database administrators can read sensitive data in production without leaving an audit trail.

    Why it's wrong here

    Session recording captures activity during privileged sessions, which helps with auditability, but database administrators with legitimate access can still read sensitive data during an approved session. JIT does not prevent authorized reading, nor does it mask data. The risk of unauthorized data viewing requires separate controls such as data masking or separation of duties.

  • ✓

    The risk that unused or stale privileged accounts accumulate and are exploited by attackers or insiders.

    Why this is correct

    Standing privileged accounts persist indefinitely and are often forgotten, creating a large attack surface. JIT access grants privileges only when needed, for a limited time, with approval and session recording, so dormant entitlements no longer exist. This directly reduces the risk of exploitation of stale or unused privileged accounts by both external attackers and malicious insiders.

  • ✗

    The risk of credential stuffing attacks against the single sign-on portal used by all employees.

    Why it's wrong here

    Credential stuffing targets authentication endpoints with reused passwords from other breaches. JIT privileged access does not change how the SSO portal authenticates ordinary users, and the portal remains exposed regardless of how privileged entitlements are granted. This risk requires controls such as MFA, breached-password screening, and rate limiting, not JIT provisioning.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.