CISSP Identity and Access Management Practice Question
An organization implements Privileged Access Management (PAM) and wants to reduce the risk of standing privileges. Which approach grants temporary elevated access only when needed?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Just-in-time access
Just-in-time (JIT) access provides time-limited privileges that are granted on demand, reducing the attack surface.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Session recording
Why it's wrong here
Session recording is a detective control within PAM that captures video and metadata of privileged user activity for auditing, compliance, and forensic analysis. While crucial for accountability, it does not actively manage or limit the *duration* of the privileges themselves. Its function is to observe and record, not to provision or de-provision access dynamically based on time or need.
- ✗
Password vaulting
Why it's wrong here
Password vaulting is a foundational PAM component that securely stores, manages, and rotates credentials for privileged accounts, preventing direct user knowledge of passwords. Its primary function is to protect static credentials and facilitate secure access to systems without exposing the password. However, it does not inherently provide mechanisms to grant temporary, time-limited access to resources, as its focus is on secure credential management rather than dynamic privilege elevation.
- ✗
Break-glass accounts
Why it's wrong here
Break-glass accounts are pre-configured, highly privileged emergency access accounts designed for use during critical system failures or disaster recovery scenarios when standard access methods are unavailable. These accounts are intended for exceptional circumstances and are typically subject to stringent monitoring and approval processes. They are not designed for routine, temporary privilege elevation for specific tasks, which is the core function of just-in-time access.
- ✓
Just-in-time access
Why this is correct
Just-in-time (JIT) access is a core principle of modern Privileged Access Management that grants elevated privileges to users only when they are needed, for the specific task at hand, and for a strictly limited duration. This approach significantly reduces the attack surface by minimizing the time privileged accounts exist with standing access. Once the task is completed or the time limit expires, the elevated privileges are automatically revoked, aligning perfectly with the goal of managing privilege duration.
Go deeper
Related to this question
Learn chapter
Identity and Access Management (IAM)
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
Privileged access management
Privileged access management is a cybersecurity practice that controls and monitors the elevated access rights of users who have special permissions to critical systems and data.
About these practice questions
Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.