220-1102 exam dumps

220-1102 practice question 350 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 350

Single answerPrivileged access management (PAM)

A help desk team supports 150 Windows workstations. Technicians currently use a shared local Administrator account to install drivers, update software, and troubleshoot issues. During a security review, management identifies that the shared admin password is rarely changed, actions cannot be traced to a specific technician, and users sometimes learn the password when a technician types it at their desk. The company wants to reduce risk while still allowing technicians to perform administrative tasks when needed. Which solution BEST addresses these concerns?

  1. A

    Implement a privileged access management (PAM) solution that provides unique, time-limited administrative credentials and logs each privileged session

  2. B

    Keep the shared Administrator account, but require technicians to change the password at the end of each week

  3. C

    Give each technician a standard user account for daily work and a separate named administrator account with no additional controls

  4. D

    Store the local Administrator password in an internal spreadsheet that only IT managers can access

Show answer and explanation

Correct answer: A

Explanation

The best answer is the PAM solution because it applies core security best practices for managing privileged accounts: least privilege, accountability, credential protection, and auditing. In a real support environment, PAM helps prevent technicians from relying on persistent shared administrator passwords. Instead, privileges can be granted only when needed, often for a limited time, and tied to a specific individual. This improves traceability and reduces the attack surface if a credential is exposed. The scenario specifically highlights common risks that PAM is meant to solve: shared admin passwords, lack of user-level attribution, and password disclosure during support visits. Best-practice guidance from major security frameworks and vendors consistently recommends minimizing standing administrative access, avoiding shared privileged credentials, rotating privileged passwords, and maintaining audit logs for administrative actions.

  • A. Correct.

    Correct. A PAM solution is designed to control, monitor, and audit elevated access. Using unique credentials or just-in-time elevation reduces password sharing, improves accountability, and limits how long privileged access exists. Session logging and credential checkout also help with traceability and incident investigation. This directly addresses the problems of shared credentials, poor auditing, and password exposure.

  • B. Incorrect.

    Incorrect. Rotating a shared password weekly is better than never changing it, but it does not solve the core issues of shared accountability and password exposure. Multiple technicians would still use the same privileged account, making it difficult to determine who performed a specific action. It also does not provide session auditing or just-in-time access.

  • C. Incorrect.

    Incorrect. Separate admin accounts are better than using one account for everything and support least privilege for daily work, but by themselves they do not fully address privileged access management concerns. Without additional controls such as time-based elevation, credential vaulting, approval workflows, or session logging, there is still greater standing privilege than necessary and less oversight than a PAM solution provides.

  • D. Incorrect.

    Incorrect. Storing administrator passwords in a spreadsheet, even if access is limited, is not a secure or manageable PAM practice. Spreadsheets do not provide automated password rotation, just-in-time access, checkout controls, or reliable session auditing. This approach increases the risk of credential leakage and weakens accountability.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam