Courseiva
Access Controls →hardMultiple Choice

SSCP Access Controls Practice Question

An organization implements a Privileged Access Management (PAM) solution. Which capability best describes granting temporary administrative rights just when needed?

⚠ Common exam trap

SSCP often tests the distinction between PAM capabilities that manage credentials (vaulting), audit sessions (recording), or analyze roles (mining) versus those that actually grant time-bound access (JIT) — candidates who focus on 'privileged access' broadly pick the wrong capability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Just-in-time provisioning

Just-in-time (JIT) provisioning grants elevated privileges only for the duration they are needed, then automatically revokes them. This directly matches the requirement of temporary administrative rights granted on demand. It reduces standing privilege and the window of exposure if credentials are compromised.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Session recording

    Why it's wrong here

    Session recording captures privileged sessions for auditing and forensic review after access occurs. It provides accountability, not authorisation, so it cannot grant temporary administrative rights; just-in-time elevation is the capability that issues time-bound privileged access on request.

  • ✓

    Just-in-time provisioning

    Why this is correct

    Just-in-time provisioning grants elevated privileges only for the duration of a specific task, then revokes them automatically. This directly satisfies the PAM requirement for temporary administrative rights issued on demand, eliminating standing access. Unlike permanent role assignment, it enforces least privilege by limiting the exposure window during which credentials could be abused.

  • ✗

    Password vaulting

    Why it's wrong here

    Password vaulting stores and rotates privileged credentials, then checks them out to authorised users. It controls credential custody rather than the timing of rights, so it cannot itself grant temporary administrative rights; just-in-time elevation is the capability that issues time-bound privileged access.

  • ✗

    Role mining

    Why it's wrong here

    Role mining analyses existing entitlements to propose role definitions, supporting role-based access design and certification. It does not grant rights on demand; just-in-time elevation is performed by time-bound privileged access workflows that issue credentials or entitlements only when requested.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.