CISSP Identity and Access Management Practice Question
An organization wants to provide just-in-time administrative access to servers, with session recording and password vaulting. Which solution is best suited?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Privileged Access Management (PAM)
Privileged Access Management (PAM) provides just-in-time access, session recording, password vaulting, and break-glass accounts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Privileged Access Management (PAM)
Why this is correct
Privileged Access Management (PAM) solutions are specifically engineered to secure, manage, and monitor highly sensitive administrative accounts and access to critical systems. They enforce just-in-time (JIT) access, granting elevated permissions only when an administrator needs them for a specific task and for a limited duration, thereby significantly minimizing the attack surface. PAM also typically includes essential features like session recording, password vaulting, and comprehensive audit trails, which are crucial for compliance and incident response related to high-risk administrative operations.
- ✗
Identity as a Service (IDaaS)
Why it's wrong here
Identity as a Service (IDaaS) provides cloud-based identity and access management (IAM) services, encompassing user provisioning, authentication, and authorization for various applications, often across different cloud environments. While it effectively manages general user identities and their lifecycle, its primary focus is not on the specialized, granular control, monitoring, and just-in-time elevation of *privileged* administrative accounts. IDaaS typically lacks the specific features like session recording, secure credential vaulting, or dynamic privilege elevation tailored for high-risk administrative access.
- ✗
Single Sign-On (SSO)
Why it's wrong here
Single Sign-On (SSO) streamlines the authentication process by allowing users to access multiple independent software systems with a single set of credentials after authenticating once. Its core function is to enhance user convenience and reduce password fatigue across various applications, not to manage or monitor privileged access or provide just-in-time elevation of administrative rights. SSO does not inherently offer features like session recording, password vaulting, or time-limited access for elevated privileges, which are critical for securing administrative functions.
- ✗
Role-Based Access Control (RBAC)
Why it's wrong here
Role-Based Access Control (RBAC) is an authorization model that grants or restricts system access to users based on their assigned roles within an organization. While RBAC effectively manages static permissions by grouping users into roles with predefined access levels, it does not inherently provide dynamic, just-in-time elevation of privileges for administrative tasks. RBAC also lacks the advanced security features like session monitoring, recording of administrative actions, or secure credential vaulting that are essential for robust privileged access management.
Go deeper
Related to this question
Learn chapter
Identity and Access Management (IAM)
Key term
Privileged access management
Privileged access management is a cybersecurity practice that controls and monitors the elevated access rights of users who have special permissions to critical systems and data.
Key term
Just-in-time access
Just-in-time access is a security method that grants users elevated permissions only for a limited time exactly when they need them, then automatically removes those permissions.
About these practice questions
Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.