CompTIA Security+ (SY0-701)Security OperationsMedium

An organization wants administrators to check out credentials from a centralized vault for a limited session, with all password rotations and usage automatically logged for audit purposes, rather than administrators memorizing static passwords. Which solution best meets this requirement?

  1. ASingle sign-on (SSO)
  2. BNetwork access control (NAC)
  3. CRole-based access control (RBAC)
  4. DPrivileged access management (PAM) solution
Show answer & explanation

Correct answer: D. Privileged access management (PAM) solution

A PAM solution centrally vaults, rotates, and audits privileged credentials, issuing temporary checkout access instead of allowing administrators to know static passwords. SSO reduces authentication prompts across applications but doesn't manage privileged credential vaulting, RBAC assigns permissions by job role, and NAC governs network admission.

Why the other options are wrong

  • A. SSO simplifies authentication across apps but doesn't vault privileged passwords.
  • B. NAC enforces device compliance for network access, unrelated to credential vaulting.
  • C. RBAC assigns permissions based on role, not credential vaulting/rotation.

Privileged Access Management (PAM)

A solution that centrally stores, rotates, and audits privileged account credentials, granting temporary checkout access instead of persistent knowledge of passwords.

  • Automatically rotates privileged passwords
  • Logs all checkout and usage sessions
  • Reduces standing privileged credential exposure

Memory trick: PAM is a locked key cabinet — check out the key, use it, return it, logged every time.

More Security Operations questions