Courseiva
Identity and Access ManagementhardMultiple ChoiceObjective-mapped

CISSP Identity and Access Management Practice Question

An organization implements Privileged Access Management (PAM) and wants to reduce the risk of standing privileges. Which approach grants temporary elevated access only when needed?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Just-in-time access

Just-in-time (JIT) access provides time-limited privileges that are granted on demand, reducing the attack surface.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Session recording

    Why it's wrong here

    Session recording is a detective control within PAM that captures video and metadata of privileged user activity for auditing, compliance, and forensic analysis. While crucial for accountability, it does not actively manage or limit the *duration* of the privileges themselves. Its function is to observe and record, not to provision or de-provision access dynamically based on time or need.

  • Password vaulting

    Why it's wrong here

    Password vaulting is a foundational PAM component that securely stores, manages, and rotates credentials for privileged accounts, preventing direct user knowledge of passwords. Its primary function is to protect static credentials and facilitate secure access to systems without exposing the password. However, it does not inherently provide mechanisms to grant temporary, time-limited access to resources, as its focus is on secure credential management rather than dynamic privilege elevation.

  • Break-glass accounts

    Why it's wrong here

    Break-glass accounts are pre-configured, highly privileged emergency access accounts designed for use during critical system failures or disaster recovery scenarios when standard access methods are unavailable. These accounts are intended for exceptional circumstances and are typically subject to stringent monitoring and approval processes. They are not designed for routine, temporary privilege elevation for specific tasks, which is the core function of just-in-time access.

  • Just-in-time access

    Why this is correct

    Just-in-time (JIT) access is a core principle of modern Privileged Access Management that grants elevated privileges to users only when they are needed, for the specific task at hand, and for a strictly limited duration. This approach significantly reduces the attack surface by minimizing the time privileged accounts exist with standing access. Once the task is completed or the time limit expires, the elevated privileges are automatically revoked, aligning perfectly with the goal of managing privilege duration.

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.