Microsoft Cybersecurity Architect (SC-100)Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategiesHard
An energy utility company operates critical infrastructure systems that are subject to NERC CIP (North American Electric Reliability Corporation Critical Infrastructure Protection) standards. The cybersecurity architect must ensure that remote access to these systems is highly secure and auditable. Which technical strategy provides the strongest control for managing and monitoring privileged remote access in compliance with NERC CIP?
- AAllowing only on-site physical access to critical systems to eliminate remote access risks.
- BDeploying a Privileged Access Management (PAM) solution that includes session recording, just-in-time access, and multi-factor authentication (MFA).
- CImplementing direct RDP/SSH access from administrator workstations with strong passwords.
- DUtilizing a VPN for all remote access without additional access controls.
Show answer & explanationAnswer & explanation
Correct answer: B. Deploying a Privileged Access Management (PAM) solution that includes session recording, just-in-time access, and multi-factor authentication (MFA).
A PAM solution with session recording, just-in-time access, and MFA directly addresses NERC CIP requirements for strict control over privileged access, providing comprehensive auditing, least privilege enforcement, and robust authentication for critical systems.
Why the other options are wrong
- A. Eliminating remote access is often impractical for operational efficiency and does not address the need for secure management of privileged access when physical access is required.
- C. Direct RDP/SSH with only strong passwords is insufficient for NERC CIP, lacking granular control, session monitoring, and advanced authentication mechanisms.
- D. A VPN provides a secure tunnel but does not offer the granular access controls, session management, or comprehensive auditing required for privileged access to critical infrastructure under NERC CIP.
Privileged Access Management (PAM)
PAM solutions manage and secure privileged accounts, credentials, and sessions, enforcing least privilege and providing comprehensive auditing capabilities.
- Controls access to sensitive systems and data.
- Reduces the attack surface by limiting privileged credential exposure.
- Enables session recording and auditing for compliance and forensics.
Memory trick: PAM Protects Critical Remote Access