SY0-701 exam dumps

SY0-701 practice question 374 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 374

Single answerEphemeral credentials

A company is moving its administrative access model from shared service-account passwords to a more secure approach. The security team wants administrators to authenticate through the corporate identity provider and receive credentials that automatically expire after a short period. They also want to reduce the impact of credential theft from scripts, logs, or memory dumps on jump servers. Which solution BEST meets these requirements?

  1. A

    Issue short-lived credentials after successful authentication and require admins to request new credentials for each privileged session

  2. B

    Store administrator passwords in an encrypted spreadsheet and require staff to change them every 90 days

  3. C

    Deploy a shared local administrator account on all jump servers and rotate its password weekly

  4. D

    Assign permanent API keys to each administrator and restrict their use to corporate IP addresses

Show answer and explanation

Correct answer: A

Explanation

The best answer is to issue short-lived, automatically expiring credentials after successful authentication. This is the core idea behind ephemeral credentials: reduce the lifetime of secrets so that compromise has limited value and duration. In real environments, this is commonly implemented with temporary tokens, just-in-time privileged access, or short-term cloud/session credentials issued by an identity provider, privileged access management system, or security token service. This approach supports accountability because credentials are tied to an individual session rather than a shared account. It also aligns with security best practices from zero trust and least privilege models, which emphasize minimizing standing privileges and reducing reliance on long-lived secrets. Guidance from organizations such as NIST, including principles in NIST SP 800-63 for digital identity and NIST SP 800-207 for zero trust architecture, supports strong authentication, limited privilege duration, and reducing persistent credential exposure.

  • A. Correct.

    Correct. Ephemeral credentials are designed to be short-lived and automatically expire, which limits the usefulness of stolen credentials. Issuing temporary credentials after authentication through an identity provider aligns with modern privileged access and zero trust practices. This approach reduces exposure in logs, scripts, and memory because the credentials have a narrow validity window and can be scoped to a specific session or task.

  • B. Incorrect.

    Incorrect. Encrypting a spreadsheet and rotating passwords every 90 days is still a static credential model. Even if the file is protected, the passwords remain long-lived secrets that can be copied, reused, or exposed. This does not provide the automatic expiration and per-session access control expected from ephemeral credentials.

  • C. Incorrect.

    Incorrect. Rotating a shared local administrator password weekly is better than never changing it, but it still relies on a shared, reusable credential. Shared accounts reduce accountability and do not minimize the value of a stolen credential during the week it remains valid. This is not equivalent to issuing time-bound credentials tied to an authenticated individual.

  • D. Incorrect.

    Incorrect. Permanent API keys are long-lived credentials, even if use is limited by source IP. IP restrictions may reduce some risk, but they do not solve the core problem of credential reuse or theft. If the key is exposed in a script, log, or memory dump, it may remain valid until manually revoked or rotated.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam