SY0-701 exam dumps

SY0-701 practice question 372 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 372

Single answerPrivileged access management tools: Just-in-time permissions , Password vaulting

A company is tightening controls over administrator access after an internal audit found that server administrators share a common root password for Linux systems and keep standing domain admin rights assigned to their accounts. The security manager wants to reduce the risk of credential theft and limit how long elevated access exists, while still allowing administrators to perform emergency maintenance after hours. Which solution BEST meets these requirements?

  1. A

    Deploy a privileged access management solution that stores administrator credentials in a password vault and grants just-in-time elevation only for approved maintenance windows

  2. B

    Require administrators to change the shared root password at the end of every shift and document the new password in an encrypted spreadsheet on a file share

  3. C

    Create separate administrator accounts for each employee and permanently assign the necessary privileged roles so work can begin immediately when needed

  4. D

    Enable single sign-on for all administrative systems so administrators can use their normal user passwords to access servers without additional prompts

Show answer and explanation

Correct answer: A

Explanation

The best answer is the PAM solution with password vaulting and just-in-time elevation. Password vaulting protects and manages privileged credentials by centralizing storage, restricting access, logging usage, and often rotating passwords after use. JIT permissions reduce the attack surface by eliminating unnecessary standing privileges and granting elevated rights only for a limited duration after approval or policy-based checks. Together, these controls support least privilege, separation of duties, and accountability.

This approach is consistent with broadly accepted guidance such as NIST's recommendations on least privilege, privileged account management, and restricting administrative access. Security best practices also emphasize avoiding shared administrator credentials, minimizing persistent privileged access, and using centralized auditing for sensitive account activity. In a real environment, PAM tools commonly provide credential checkout, approval workflows, session logging, and temporary privilege elevation, all of which directly address the risks identified in the scenario.

  • A. Correct.

    Correct. This directly addresses both audit findings: password vaulting removes the need to share static privileged credentials, and just-in-time (JIT) permissions reduce standing privileges by granting elevated access only when needed and only for a limited time. This is a core privileged access management (PAM) use case and aligns with least privilege and administrative access control best practices.

  • B. Incorrect.

    Incorrect. Although changing passwords more frequently may seem more secure, this still relies on a shared privileged credential, which weakens accountability and increases the chance of disclosure. Storing the password in an encrypted spreadsheet on a file share is not equivalent to a password vault because it typically lacks controlled checkout, rotation, auditing, approval workflows, and session oversight that PAM tools provide.

  • C. Incorrect.

    Incorrect. Separate admin accounts improve accountability compared to shared accounts, but permanently assigning privileged roles leaves standing privileges in place. That does not meet the requirement to limit how long elevated access exists. The scenario specifically calls for reducing persistent administrative rights, which JIT access is designed to solve.

  • D. Incorrect.

    Incorrect. Single sign-on (SSO) can improve usability and centralize authentication, but it does not solve the core problems described here. SSO does not provide password vaulting for privileged shared credentials, nor does it inherently remove standing administrative privileges. In some cases, using normal user credentials for administration can also increase risk if those accounts are compromised.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam