CompTIA SecurityX (CAS-005)Security EngineeringEasy
A security architect is implementing a Privileged Access Management (PAM) solution. As part of this, the organization requires that administrative access to critical systems is granted only for the duration of a specific task and automatically revoked afterward. This approach aims to minimize the attack surface associated with standing privileges. Which access control principle is being implemented here?
- ALeast Privilege
- BRole-Based Access Control (RBAC)
- CAttribute-Based Access Control (ABAC)
- DJust-in-Time (JIT) Access
Show answer & explanationAnswer & explanation
Correct answer: D. Just-in-Time (JIT) Access
Just-in-Time (JIT) Access is an access control principle where permissions are granted only when needed, for a limited duration, and automatically revoked once the task is complete or the time expires. This directly addresses the requirement to minimize the attack surface by eliminating standing privileges.
Why the other options are wrong
- A. Least Privilege is a fundamental security principle of granting minimum necessary permissions, but JIT is a specific mechanism to implement it dynamically, going beyond static assignment.
- B. RBAC assigns permissions based on a user's role, but it doesn't inherently imply temporary or time-limited access.
- C. ABAC grants access based on a combination of attributes (user, resource, environment), but it doesn't explicitly define the temporary, time-bound nature of access as a core principle.
Just-in-Time (JIT) Access
An access control principle where elevated privileges are granted only at the moment they are needed, for a limited duration, and automatically revoked afterward.
- Minimizes standing privileges
- Reduces attack surface
- Often integrated with PAM solutions
Memory trick: JIT Access: Just In Time, Just Enough, Just Gone!