CompTIA Cloud Essentials+ (CLO-002)Governance, Risk, Compliance and SecurityMedium

A cloud infrastructure team wants to reduce risk from standing administrative credentials. They implement a system where administrators must check out temporary, time-limited elevated credentials from a secure vault to perform specific tasks, and every privileged session is recorded for later audit. Which security approach does this describe?

  1. AFederated Identity Management
  2. BRole-Based Access Control (RBAC)
  3. CPrivileged Access Management (PAM)
  4. DSingle Sign-On (SSO)
Show answer & explanation

Correct answer: C. Privileged Access Management (PAM)

Privileged Access Management (PAM) solutions secure, control, and monitor access for administrative accounts, often using vaults for just-in-time credential checkout and session recording to reduce the risk of standing privileged access being compromised.

Why the other options are wrong

  • A. Federated identity management enables trust between separate identity domains, not privileged credential vaulting.
  • B. RBAC assigns permissions based on job role but does not specifically address temporary credential checkout or session recording.
  • D. SSO allows a single authentication event to grant access to multiple systems, unrelated to credential vaulting.

Privileged Access Management (PAM)

A security discipline that secures, controls, and monitors access for privileged/administrative accounts, often using credential vaulting, just-in-time access, and session recording.

  • Reduces risk of standing privileged credentials
  • Uses vaults for time-limited credential checkout
  • Session recording enables auditing and forensics
  • Distinct from general IAM which covers all user types

Memory trick: 'PAM guards the crown jewels' by locking admin keys in a vault.

More Governance, Risk, Compliance and Security questions