Courseiva
easyMultiple ChoiceObjective-mapped

CISSP Practice Question: Is a key principle of privileged access…

Which of the following is a key principle of privileged access management (PAM)?

⚠ Common exam trap

Watch out — candidates often confuse PAM with general identity management and choose 'shared accounts for simplicity' (Option A), failing to recognize that PAM specifically enforces individual accountability and credential rotation, not shared access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Monitor and audit privileged account usage

Privileged Access Management (PAM) is centered on the principle of least privilege and the need to control, monitor, and audit the use of privileged accounts (e.g., root, domain admin). Option B is correct because continuous monitoring and auditing of privileged account usage is a foundational PAM requirement, enabling detection of misuse, lateral movement, and privilege escalation. Without auditing, organizations cannot enforce accountability or respond to security incidents involving high-risk accounts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Use shared accounts for simplicity

    Why it's wrong here

    Using shared accounts for privileged access significantly compromises security by eliminating individual accountability. When multiple users share credentials, it becomes impossible to definitively trace specific actions back to a single person, hindering forensic investigations and making it difficult to identify malicious activity or policy violations. This practice directly undermines the principle of non-repudiation, which is crucial for maintaining a secure and auditable environment.

  • Monitor and audit privileged account usage

    Why this is correct

    Monitoring and auditing privileged account usage is a cornerstone of effective privileged access management (PAM). This continuous oversight enables the prompt detection of unauthorized activities, policy violations, or suspicious behavior that could indicate a compromise. Regular audits provide irrefutable evidence for accountability, support compliance requirements, and are critical for post-incident forensic analysis, thereby significantly reducing operational risk.

  • Grant all users administrative rights for efficiency

    Why it's wrong here

    Granting all users administrative rights for perceived efficiency is a severe security misstep that directly violates the fundamental principle of least privilege. This practice vastly expands the attack surface, as every user account becomes a potential vector for system-wide compromise if breached. It also increases the likelihood of accidental misconfigurations or malicious actions causing widespread damage, making the environment inherently insecure and difficult to manage.

  • Disable logging for performance

    Why it's wrong here

    Disabling logging for performance optimization, particularly for privileged access activities, is a critical security vulnerability. Without comprehensive logs, organizations lose the ability to detect anomalous behavior, track changes, or conduct forensic investigations following a security incident. This lack of visibility makes it impossible to establish accountability, comply with regulatory mandates, or effectively respond to threats, leaving the system blind to potential compromises.

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.