Courseiva
hardMultiple Select

CISSP Practice Question: Which THREE are components of a privileged access…

Which THREE are components of a privileged access management (PAM) solution?

⚠ Common exam trap

Watch out — candidates often confuse general security best practices (like password complexity or MFA for all users) with the specific architectural components that define a PAM solution, leading them to select options that are not core PAM elements.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Credential vaulting

Credential vaulting (A) is a core PAM component because it stores privileged account credentials in an encrypted repository, allowing checkout, rotation, and brokering so administrators never need to know the underlying passwords. Just-in-time privilege elevation (D) is correct because PAM solutions grant elevated rights only for the specific task and time window needed, then automatically revoke them, reducing standing privileged access. Session recording and monitoring (E) is also correct because PAM platforms proxy and record privileged sessions (e.g., SSH, RDP) to provide audit trails, keystroke logging, and real-time threat detection. Password complexity rules (B) are a general identity/password-policy control, not a defining PAM component, and multi-factor authentication for all users (C) is broader than PAM—MFA may integrate with PAM, but applying it to every user is an enterprise-wide authentication requirement rather than a PAM component itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Credential vaulting

    Why this is correct

    Credential vaulting is a fundamental component of PAM, securely centralizing and managing the lifecycle of privileged credentials, such as administrator passwords, SSH keys, and API keys. It eliminates hardcoded credentials, enforces automated rotation, and controls access to these sensitive assets, thereby significantly reducing the risk of credential theft and misuse by preventing direct user knowledge of the actual passwords.

  • ✗

    Password complexity rules

    Why it's wrong here

    Password complexity rules, while a crucial element of overall information security, are a general security policy applicable to all user accounts, not a unique or exclusive component of a Privileged Access Management (PAM) system. PAM's primary focus is on managing and securing the *access* to privileged accounts, often by vaulting credentials and abstracting them from end-users, rather than solely enforcing complexity for passwords that users might directly know.

  • ✗

    Multi-factor authentication for all users

    Why it's wrong here

    Multi-factor authentication (MFA) for all users is a vital security control that strengthens authentication across an entire organization, enhancing the security posture for both privileged and non-privileged accounts. While PAM solutions often integrate with MFA to secure access to the PAM system itself or to gate privilege elevation, MFA for "all users" is a broader Identity and Access Management (IAM) strategy and not a distinct, core component *exclusive* to the operational scope of a Privileged Access Management system.

  • ✓

    Just-in-time privilege elevation

    Why this is correct

    Just-in-time (JIT) privilege elevation is a core PAM component that dynamically grants users elevated permissions only for a specific, limited duration and purpose, typically upon an approved request. This mechanism minimizes the window of opportunity for attackers to exploit standing privileged access, significantly reducing the attack surface by enforcing the principle of least privilege and ensuring privileges are granted only when absolutely necessary.

  • ✓

    Session recording and monitoring

    Why this is correct

    Session recording and monitoring is an essential PAM capability that captures and logs all activities performed during privileged sessions, including keystrokes, commands executed, and screen recordings. This provides an immutable audit trail for forensic analysis, compliance reporting, and real-time threat detection, ensuring comprehensive accountability and visibility into privileged operations, which is critical for identifying and responding to misuse or compromise.

About these practice questions

Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.