CompTIA SecurityX (CAS-005)Security EngineeringEasy

A security architect is implementing a Privileged Access Management (PAM) solution. As part of this, they want to ensure that administrative access to critical systems is granted only when explicitly requested and for a strictly limited duration, automatically revoking access once the task is complete or the time limit expires. This minimizes the window of opportunity for attackers to exploit standing privileges. Which PAM concept does this BEST describe?

  1. AJust-in-Time (JIT) Access
  2. BRole-Based Access Control (RBAC)
  3. CMulti-Factor Authentication (MFA)
  4. DSegregation of Duties (SoD)
Show answer & explanation

Correct answer: A. Just-in-Time (JIT) Access

Just-in-Time (JIT) Access is a core PAM concept that grants privileged access only when it is needed, for the duration it is needed, and then automatically revokes it. This directly addresses the requirement to minimize the window of opportunity for attackers by eliminating standing privileges.

Why the other options are wrong

  • B. RBAC defines roles and permissions but doesn't inherently manage the temporary nature of access.
  • C. MFA strengthens authentication but doesn't manage the duration or scope of privileged access itself.
  • D. SoD prevents a single individual from completing all parts of a critical process, which is a different security control.

Just-in-Time (JIT) Access

A security principle where privileged access is granted only for the specific task at hand, for a limited duration, and automatically revoked afterward, thereby minimizing the attack surface.

  • Access granted only when needed.
  • Time-limited and task-specific.
  • Automatically revoked to minimize standing privileges.

Memory trick: JIT access gives you privileges JUST IN TIME.

More Security Engineering questions