ISC2 CC Access Controls Concepts Practice Question
An organization is designing a privileged access management (PAM) solution. Which THREE of the following are best practices for managing privileged accounts? (Select three.)
⚠ Common exam trap
CC often tests whether candidates can spot obvious PAM anti-patterns (shared root password, plaintext storage) versus genuine best practices (least privilege, separate accounts, session monitoring) — the distractors are deliberately extreme to test fundamentals.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Applying the principle of least privilege to admin accounts
Option C is correct because applying the principle of least privilege ensures administrators receive only the minimum rights needed to perform their duties, reducing the attack surface and limiting damage from compromised accounts. Option D is correct because using separate administrative accounts for daily tasks and privileged tasks prevents day-to-day activities such as email and web browsing from exposing highly privileged credentials to malware or phishing. Option E is correct because implementing session recording and monitoring of privileged activities provides accountability, deters insider misuse, and creates an audit trail for forensic investigation of privileged actions. Options A and B are not best practices: sharing the root password among all administrators destroys individual accountability and violates least privilege, while storing privileged passwords in an unencrypted text file exposes them to any user or process with file access and fails basic confidentiality controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Sharing the root password among all administrators for convenience
Why it's wrong here
Sharing the root password destroys individual accountability and non-repudiation, since audit logs can no longer attribute actions to one administrator. It is tempting because it removes the friction of multiple credentials, but shared accounts suit only low-risk, non-privileged service access where attribution is not required.
- ✗
Storing privileged passwords in an unencrypted text file
Why it's wrong here
Plaintext storage exposes privileged credentials to anyone with file or backup access, defeating the purpose of a PAM vault. It is tempting because it is convenient and requires no infrastructure, but unencrypted storage suits only non-sensitive public configuration data, never credentials granting elevated rights.
- ✓
Applying the principle of least privilege to admin accounts
Why this is correct
Applying least privilege limits each admin account to only the permissions its role requires, shrinking the blast radius if credentials are compromised. For a PAM design, this directly satisfies the stem's constraint by removing standing excess rights, so privileged accounts cannot perform actions beyond their defined duties.
- ✓
Using separate administrative accounts for daily tasks and privileged tasks
Why this is correct
Separating day-to-day and privileged accounts limits exposure of high-impact credentials, satisfying the least-privilege and credential-isolation requirements of a PAM design. A compromised standard account cannot directly perform administrative actions, and privileged sessions remain auditable and distinct, reducing lateral movement and standing access risk.
- ✓
Implementing session recording and monitoring of privileged activities
Why this is correct
Session recording and monitoring satisfy the audit and accountability requirement for privileged access management by capturing exactly what each administrator does during elevated sessions. This deters misuse and supplies forensic evidence when investigating incidents, directly addressing the stem's PAM design goal of controlling and tracing privileged activity across the organisation.
Go deeper
Related to this question
Learn chapter
Incident Response and Management
Key term
Audit trail
An audit trail is a chronological record of events, changes, or activities in a system that provides evidence of who did what, when, and from where.
Key term
Privileged access
Privileged access is a special level of permission that allows a user or system to perform high-impact actions like installing software, changing system settings, or accessing sensitive data across an IT environment.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.