CompTIA SecurityX (CAS-005)Security EngineeringMedium
A security architect is implementing a Privileged Access Management (PAM) solution. As part of the least privilege principle, users should only be granted elevated permissions for a specific duration or task. Which PAM feature BEST supports this requirement?
- APassword vaulting and rotation
- BSession recording and monitoring
- CMulti-factor authentication (MFA) for privileged accounts
- DJust-in-Time (JIT) provisioning and access
Show answer & explanationAnswer & explanation
Correct answer: D. Just-in-Time (JIT) provisioning and access
Just-in-Time (JIT) provisioning and access grants elevated privileges only when needed, for a specific task, and for a limited duration. This directly implements the principle of least privilege and reduces the window of opportunity for attackers to exploit standing privileges.
Why the other options are wrong
- A. Password vaulting and rotation secure the credentials themselves but don't inherently control the duration or scope of access once the credential is used.
- B. Session recording and monitoring is an auditing and accountability feature, not a mechanism for granting temporary privileges.
- C. MFA strengthens authentication but doesn't manage the duration or scope of the privileges granted after successful authentication.
Just-in-Time (JIT) Access
A security principle where users are granted elevated privileges only at the moment they are needed, for a specific task, and for a limited duration.
- Minimizes standing privileges.
- Reduces attack surface.
- Enhances 'least privilege' and 'zero trust' principles.
Memory trick: JIT access gives privileges just for now, not forever.