CompTIA SecurityX (CAS-005)Security EngineeringHard

A security architect is implementing a Privileged Access Management (PAM) solution. As part of this initiative, the architect aims to minimize the window of opportunity for attackers to exploit privileged credentials. The solution should grant elevated permissions to users or services only when they are explicitly needed for a specific task and revoke them immediately after the task is completed or a predefined time limit expires. This security principle is known as:

  1. AAttribute-Based Access Control (ABAC)
  2. BJust-in-Time (JIT) Access
  3. CLeast Privilege
  4. DRole-Based Access Control (RBAC)
Show answer & explanation

Correct answer: B. Just-in-Time (JIT) Access

Just-in-Time (JIT) access is a core principle in PAM that grants elevated privileges only for the duration of a specific task and then automatically revokes them, significantly reducing the attack surface for privileged accounts beyond what static RBAC or ABAC can achieve alone.

Why the other options are wrong

  • A. ABAC grants access based on a combination of attributes, offering fine-grained control, but doesn't inherently imply temporary, time-bound access.
  • C. Least Privilege is a fundamental security principle (granting only necessary permissions), but JIT is a *method* of implementing least privilege for *privileged* accounts on a temporary basis, going beyond merely defining static minimum permissions.
  • D. RBAC assigns permissions based on roles, but these roles are typically persistent, not temporary, and don't address the 'when needed' aspect.

Just-in-Time (JIT) Access

A security principle and PAM feature that grants elevated access privileges to users or systems only when they are needed, for a specific duration, and revoking them automatically thereafter.

  • Minimizes exposure of privileged credentials
  • Reduces attack surface for privileged accounts
  • A key component of modern PAM and Zero Trust strategies

Memory trick: JIT Access Grants Power Just For a Moment.

More Security Engineering questions