CompTIA SecurityX (CAS-005)Security EngineeringMedium

A security architect is implementing a Privileged Access Management (PAM) solution. As part of the least privilege principle, users should only be granted elevated permissions for a specific duration or task. Which PAM feature BEST supports this requirement?

  1. APassword vaulting and rotation
  2. BSession recording and monitoring
  3. CMulti-factor authentication (MFA) for privileged accounts
  4. DJust-in-Time (JIT) provisioning and access
Show answer & explanation

Correct answer: D. Just-in-Time (JIT) provisioning and access

Just-in-Time (JIT) provisioning and access grants elevated privileges only when needed, for a specific task, and for a limited duration. This directly implements the principle of least privilege and reduces the window of opportunity for attackers to exploit standing privileges.

Why the other options are wrong

  • A. Password vaulting and rotation secure the credentials themselves but don't inherently control the duration or scope of access once the credential is used.
  • B. Session recording and monitoring is an auditing and accountability feature, not a mechanism for granting temporary privileges.
  • C. MFA strengthens authentication but doesn't manage the duration or scope of the privileges granted after successful authentication.

Just-in-Time (JIT) Access

A security principle where users are granted elevated privileges only at the moment they are needed, for a specific task, and for a limited duration.

  • Minimizes standing privileges.
  • Reduces attack surface.
  • Enhances 'least privilege' and 'zero trust' principles.

Memory trick: JIT access gives privileges just for now, not forever.

More Security Engineering questions