Privileged Access Flashcards
7 cards from real CIAM practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Privileged Access flashcards as text
Which control specifically prevents a privileged user from reading their own audit logs within a PAM system?
Answer: Separation of duties
Separation of duties ensures that the person performing privileged actions is different from the person who audits those actions.
A PAM solution records every keystroke and command executed during a privileged session. What is this capability called?
Answer: Privileged session management
Privileged session management (PSM) encompasses session recording, monitoring, and control of all privileged user activities.
What is the primary purpose of a privileged access workstation (PAW)?
Answer: To provide a hardened, isolated environment for performing administrative tasks
A PAW is a dedicated, hardened workstation used exclusively for privileged tasks, reducing the attack surface for credential theft.
Which attack technique involves an adversary extracting password hashes from the LSASS process to gain privileged access?
Answer: Pass-the-hash
Pass-the-hash allows attackers to authenticate using a stolen NTLM hash without knowing the plaintext password.
In a PAM context, what does 'password vaulting' primarily accomplish?
Answer: Stores and rotates privileged credentials centrally so humans never see plaintext passwords
Password vaulting centralizes storage and automates rotation of privileged credentials, eliminating static, human-known passwords.
Which principle recommends granting privileged access only for the duration needed to complete a specific task?
Answer: Zero standing privilege
Zero standing privilege (ZSP) eliminates persistent privileged accounts by granting access on-demand and revoking it immediately after.
When a PAM system requires two authorized individuals to jointly approve and execute a privileged command, this is known as:
Answer: Dual control
Dual control requires simultaneous involvement of two authorized parties, preventing unilateral execution of sensitive privileged actions.