CompTIA SecurityX (CAS-005)Security EngineeringEasy
A security architect is implementing a Privileged Access Management (PAM) solution. As part of this, administrative users should only have elevated permissions for a limited, predefined duration when performing specific tasks, and these permissions should automatically revoke once the task is completed or the duration expires. Which access control principle is being implemented?
- ARole-Based Access Control (RBAC)
- BAttribute-Based Access Control (ABAC)
- CLeast Privilege
- DJust-in-Time (JIT) Access
Show answer & explanationAnswer & explanation
Correct answer: D. Just-in-Time (JIT) Access
Just-in-Time (JIT) Access is a security principle where privileged access is granted only when needed, for the minimum duration required, and then automatically revoked. This directly matches the scenario's requirement for 'limited, predefined duration' and 'automatically revoke' for specific tasks.
Why the other options are wrong
- A. RBAC assigns permissions based on a user's role, but doesn't inherently include temporary, auto-revoking access.
- B. ABAC grants access based on attributes (user, resource, environment), but doesn't inherently mean temporary, auto-revoking access.
- C. Least Privilege is a principle that users should only have the minimum permissions necessary, but JIT is a mechanism to enforce this dynamically for privileged access.
Just-in-Time (JIT) Access
Just-in-Time (JIT) Access is a security principle where privileged access is granted only when needed, for the minimum duration required, and then automatically revoked.
- Reduces the attack surface by minimizing standing privileges.
- Enforces the principle of least privilege dynamically.
- Commonly implemented in Privileged Access Management (PAM) solutions.
Memory trick: Access is 'just-in-time', like a library book you return promptly.