CISSP Identity and Access Management Practice Question
Which THREE of the following are components of a Privileged Access Management (PAM) solution?
⚠ Common exam trap
The trap is that SSO and self-service password reset sound like 'access management' and get lumped in with PAM — remember PAM is specifically about privileged accounts, vaulting, JIT elevation, and session auditing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Session recording
Session recording (C) is a core PAM component because it captures and audits privileged sessions (e.g., SSH, RDP) for accountability and forensic review. Just-in-time access (D) is a PAM capability that grants elevated privileges only when needed and for a limited time, reducing standing access. Password vaulting (E) is central to PAM, as it securely stores, rotates, and checks out privileged credentials. User self-service password reset (A) and single sign-on for web applications (B) are identity and access management (IAM) features, not PAM-specific components.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
User self-service password reset
Why it's wrong here
User self-service password reset allows general users to regain access to their accounts without IT intervention. While a crucial component of overall identity and access management (IAM) for improving user experience and reducing help desk load, it specifically addresses standard user accounts and does not manage, secure, or monitor privileged credentials or access paths, which is the core function of a Privileged Access Management (PAM) system.
- ✗
Single sign-on for web applications
Why it's wrong here
Single sign-on (SSO) for web applications enables users to access multiple applications with a single set of credentials, streamlining the authentication process. While SSO enhances user convenience and can be integrated into an overall identity management strategy, its primary purpose is to simplify access for all users, not specifically to manage, secure, or audit the highly sensitive administrative or system-level accounts that fall under the purview of Privileged Access Management (PAM).
- ✓
Session recording
Why this is correct
Session recording is a critical component of Privileged Access Management (PAM) that captures and archives all activities performed during a privileged session. This includes keystrokes, mouse movements, and screen content, providing an immutable audit trail. Such recordings are invaluable for forensic analysis, compliance auditing, and identifying unauthorized or suspicious actions by privileged users, enhancing accountability and security posture.
- ✓
Just-in-time access
Why this is correct
Just-in-time (JIT) access is a core PAM principle that grants privileged permissions only when explicitly requested and for a strictly limited duration. This ephemeral access model minimizes the attack surface by ensuring that privileged accounts are not persistently active, reducing the window of opportunity for attackers to exploit standing privileges. Once the task is complete or the time expires, the elevated privileges are automatically revoked.
- ✓
Password vaulting
Why this is correct
Password vaulting is a fundamental component of PAM that involves securely storing and managing highly sensitive privileged account credentials in an encrypted, centralized repository. This mechanism eliminates the need for administrators to know or directly handle these passwords, instead allowing the PAM system to retrieve and inject them automatically when privileged access is required, thereby preventing credential theft and ensuring strong password policies.
Go deeper
Related to this question
Learn chapter
Secure Network Architecture and Components
Key term
Accountability
Accountability is the security principle that ensures actions and identity are linked so that a person or system can be held responsible for their activities.
Key term
Privileged access
Privileged access is a special level of permission that allows a user or system to perform high-impact actions like installing software, changing system settings, or accessing sensitive data across an IT environment.
About these practice questions
One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.