CISSP Identity and Access Management Practice Question
An organization wants to provide just-in-time administrative access to servers, with session recording and password vaulting. Which solution is best suited?
⚠ Common exam trap
CISSP often tests the distinction between authentication/authorization controls (SSO, RBAC) and privileged session management — candidates pick SSO or RBAC because they sound like access control, missing the vaulting and recording requirements unique to PAM.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Privileged Access Management (PAM)
PAM (Privileged Access Management) solutions are purpose-built to broker, vault, and record privileged sessions — providing just-in-time elevation, credential checkout, and full session recording for administrative access to servers. Tools like CyberArk, BeyondTrust, and Delinea implement these controls natively, matching every requirement in the scenario. The other options address authentication or authorization but lack session recording and password vaulting capabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Privileged Access Management (PAM)
Why this is correct
Privileged Access Management (PAM) solutions are specifically engineered to secure, manage, and monitor highly sensitive administrative accounts and access to critical systems. They enforce just-in-time (JIT) access, granting elevated permissions only when an administrator needs them for a specific task and for a limited duration, thereby significantly minimizing the attack surface. PAM also typically includes essential features like session recording, password vaulting, and comprehensive audit trails, which are crucial for compliance and incident response related to high-risk administrative operations.
- ✗
Identity as a Service (IDaaS)
Why it's wrong here
Identity as a Service (IDaaS) provides cloud-based identity and access management (IAM) services, encompassing user provisioning, authentication, and authorization for various applications, often across different cloud environments. While it effectively manages general user identities and their lifecycle, its primary focus is not on the specialized, granular control, monitoring, and just-in-time elevation of *privileged* administrative accounts. IDaaS typically lacks the specific features like session recording, secure credential vaulting, or dynamic privilege elevation tailored for high-risk administrative access.
- ✗
Single Sign-On (SSO)
Why it's wrong here
Single Sign-On (SSO) streamlines the authentication process by allowing users to access multiple independent software systems with a single set of credentials after authenticating once. Its core function is to enhance user convenience and reduce password fatigue across various applications, not to manage or monitor privileged access or provide just-in-time elevation of administrative rights. SSO does not inherently offer features like session recording, password vaulting, or time-limited access for elevated privileges, which are critical for securing administrative functions.
- ✗
Role-Based Access Control (RBAC)
Why it's wrong here
Role-Based Access Control (RBAC) is an authorization model that grants or restricts system access to users based on their assigned roles within an organization. While RBAC effectively manages static permissions by grouping users into roles with predefined access levels, it does not inherently provide dynamic, just-in-time elevation of privileges for administrative tasks. RBAC also lacks the advanced security features like session monitoring, recording of administrative actions, or secure credential vaulting that are essential for robust privileged access management.
Go deeper
Related to this question
Learn chapter
Physical Security and Environmental Controls
Key term
Privileged access
Privileged access is a special level of permission that allows a user or system to perform high-impact actions like installing software, changing system settings, or accessing sensitive data across an IT environment.
Key term
Authorization
Authorization determines what an authenticated user is allowed to do within a system, such as accessing files, running programs, or changing settings.
About these practice questions
Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.