CompTIA Cloud Essentials+ (CLO-002)Governance, Risk, Compliance and SecurityMedium
A cloud infrastructure team wants to reduce risk from standing administrative credentials. They implement a system where administrators must check out temporary, time-limited elevated credentials from a secure vault to perform specific tasks, and every privileged session is recorded for later audit. Which security approach does this describe?
- AFederated Identity Management
- BRole-Based Access Control (RBAC)
- CPrivileged Access Management (PAM)
- DSingle Sign-On (SSO)
Show answer & explanationAnswer & explanation
Correct answer: C. Privileged Access Management (PAM)
Privileged Access Management (PAM) solutions secure, control, and monitor access for administrative accounts, often using vaults for just-in-time credential checkout and session recording to reduce the risk of standing privileged access being compromised.
Why the other options are wrong
- A. Federated identity management enables trust between separate identity domains, not privileged credential vaulting.
- B. RBAC assigns permissions based on job role but does not specifically address temporary credential checkout or session recording.
- D. SSO allows a single authentication event to grant access to multiple systems, unrelated to credential vaulting.
Privileged Access Management (PAM)
A security discipline that secures, controls, and monitors access for privileged/administrative accounts, often using credential vaulting, just-in-time access, and session recording.
- Reduces risk of standing privileged credentials
- Uses vaults for time-limited credential checkout
- Session recording enables auditing and forensics
- Distinct from general IAM which covers all user types
Memory trick: 'PAM guards the crown jewels' by locking admin keys in a vault.