ISC2 CC Access Controls Concepts Practice Question
What is the primary purpose of a Privileged Access Management (PAM) solution?
⚠ Common exam trap
Watch out — candidates often confuse PAM with general IAM or SSO solutions, as candidates may think any access management tool covers privileged access, but PAM specifically targets elevated accounts and their monitoring.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To control and monitor privileged access to critical systems
A Privileged Access Management (PAM) solution is specifically designed to secure, control, and monitor the use of privileged accounts—such as root, administrator, or service accounts—that have elevated access to critical systems. It typically provides features like credential vaulting, session recording, just-in-time access, and approval workflows to prevent misuse and detect malicious activity. Unlike general IAM or SSO tools, PAM focuses on the highest-risk accounts and enforces least privilege for administrative actions. Thus, option D accurately captures its primary purpose.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To provide single sign-on for all applications
Why it's wrong here
PAM brokers, vaults and audits privileged accounts such as root and domain administrators, whereas single sign-on authenticates ordinary users across many applications. It is tempting because PAM can include SSO-like access, but its purpose is controlling and recording elevated credentials, not general application convenience.
- ✗
To manage visitor access to the building
Why it's wrong here
Visitor access management is a physical security function, while PAM governs privileged accounts and their sessions within IT systems. It is tempting because both concern controlling who gets access, but visitor logs and badges belong to facilities security, not credential vaulting and session recording.
- ✗
To enforce password complexity for all users
Why it's wrong here
Password complexity policies apply to every account and are enforced by directory settings, not by PAM. PAM vaults, brokers and rotates credentials for privileged accounts, and monitors sessions. Complexity rules would be the answer if the question asked how to strengthen user passwords generally.
- ✓
To control and monitor privileged access to critical systems
Why this is correct
PAM brokers privileged sessions through a controlled vault, enforcing approval workflows, credential checkout and full session recording. This satisfies the scenario's need to both restrict who reaches critical systems and retain auditable evidence of every administrative action performed.
Go deeper
Related to this question
Learn chapter
Secure Network Architecture and Design
Key term
PAM
Privileged Access Management (PAM) is a security framework that controls, monitors, and audits access to critical systems and accounts with elevated permissions.
Key term
SSO
Single Sign-On (SSO) is an authentication process that allows a user to access multiple applications or systems with one set of login credentials.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.