mediumMultiple ChoiceObjective-mapped
CISSP Practice Question: An organization's security policy requires that…
An organization's security policy requires that privileged accounts have their passwords changed every 30 days and be monitored. Which solution effectively manages these requirements?
⚠ Common exam trap
Test-takers frequently confuse a general password manager (Option B) with a PAM solution, overlooking that PAM adds session monitoring, auditing, and just-in-time access for privileged accounts, which are critical for compliance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Privileged Access Management (PAM) solution
A Privileged Access Management (PAM) solution is specifically designed to manage privileged accounts, enforce password rotation policies (e.g., every 30 days), and provide detailed monitoring and auditing of privileged sessions. It automates password changes, vaults credentials, and logs all access, directly meeting the policy requirements for privileged accounts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Role-based access control
Why it's wrong here
Role-based access control (RBAC) defines what actions a user can perform based on their assigned role within a system. While fundamental for managing permissions, RBAC does not inherently provide capabilities for automated password rotation, secure credential vaulting, real-time session monitoring, or detailed audit trails specifically for privileged accounts. It focuses on authorization rules rather than the operational security and lifecycle management of high-risk credentials.
- ✗
Enterprise password manager
Why it's wrong here
An Enterprise Password Manager (EPM) primarily offers secure storage and retrieval of credentials for users and applications across an organization. While it centralizes password management and can improve user convenience, it typically lacks the specialized features required for comprehensive privileged access security. These missing features include automated, policy-driven password rotation for system accounts, real-time session recording, and granular command-level monitoring of privileged activities.
- ✓
Privileged Access Management (PAM) solution
Why this is correct
A Privileged Access Management (PAM) solution is purpose-built to secure, manage, and monitor all forms of privileged access within an organization. It provides essential capabilities such as automated password rotation for privileged accounts, secure credential vaulting, just-in-time access provisioning, and comprehensive session recording and monitoring. PAM solutions generate detailed audit trails of all privileged activities, ensuring accountability, enforcing the principle of least privilege, and significantly reducing the attack surface associated with high-risk accounts.
- ✗
Single sign-on for administrators
Why it's wrong here
Single Sign-On (SSO) for administrators streamlines the authentication process by allowing users to access multiple applications with a single set of credentials. While SSO can enhance convenience and potentially improve security by reducing password fatigue, its primary function is authentication federation. It does not inherently provide mechanisms for automated password rotation of privileged accounts, real-time monitoring of administrative sessions, or detailed auditing of specific commands executed during a privileged session, which are critical for securing high-risk access.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Privileged access
Privileged access is a special level of permission that allows a user or system to perform high-impact actions like installing software, changing system settings, or accessing sensitive data across an IT environment.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.