Courseiva
Access Controls →mediumMultiple Choice

SSCP Access Controls Practice Question

An organization has implemented a PAM solution for managing privileged accounts. Which feature allows administrators to request temporary elevated access for a specific task?

⚠ Common exam trap

SSCP often tests the confusion between PAM features that control access (vaulting, JIT) and those that monitor it (session recording), leading candidates to choose a monitoring feature when the question asks for access provisioning.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Just-in-time provisioning

Just-in-time (JIT) provisioning in a PAM solution grants elevated privileges only for the duration of a specific task and then automatically revokes them, which is exactly the 'temporary elevated access' described. It minimizes standing privileges and reduces the attack surface. Other PAM features like vaulting and session recording support security but do not provide on-demand, time-bound elevation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Session recording

    Why it's wrong here

    Session recording captures activity for audit and review; it grants no access. The scenario requires just-in-time elevation, where a request triggers time-bound privileged credentials. Recording is tempting because PAM suites bundle it alongside access workflows, and it would be the right control when the requirement is evidencing what an administrator did during an already-approved session.

  • ✓

    Just-in-time provisioning

    Why this is correct

    Just-in-time provisioning grants elevated privileges only for the duration of a specific task, then automatically revokes them. This directly satisfies the PAM requirement for temporary, task-scoped access, eliminating standing privileges that attackers could exploit. Microsoft Entra ID Privileged Identity Management implements this through time-bound role activation, requiring justification and approval before elevation.

  • ✗

    Password vaulting

    Why it's wrong here

    Password vaulting stores privileged credentials and checks them out for use, but it does not grant time-bound elevated permissions for a task. It is tempting because vaulting is central to PAM, securing and rotating administrative secrets; it would be the right control when the requirement is credential protection and audit of password retrieval rather than just-in-time role activation.

  • ✗

    Role-based access control

    Why it's wrong here

    RBAC assigns standing permissions based on role membership; it does not broker time-bound elevation requests. Just-in-time access, with approval workflows and expiry, is the PAM feature that grants temporary elevated rights for a specific task.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.