The question this module answers
What privileged access do we actually have, and how risky is it?
Layla hands Priya one instruction: find it, all of it. Priya works through nine discovery sources, from access control lists and Active Directory to logs and interviews. She sets one rule, collect once and audit forever, and follows it for every account, including the AI identities nobody hired. Six weeks later, 312 privileged accounts that nobody had on any list are recorded, owned and ranked by risk.
Module curriculum
1
Part 1: Why Discovery Comes First
Narrated slides
2
Part 2: Collect Once, Audit Forever
Narrated slides
3
Part 3: The Sources: ACLs, Roles, User Lists and Permissions
Narrated slides
4
Part 4: The AI Layer of Privileged Access
Narrated slides
5
Part 5: Active Directory, IAM and Best Practice
Narrated slides
6
Part 6: Assessment: Risk, Logs, Reviews and People
Narrated slides
7
Part 7: The Record, the Tally and the Handover
Narrated slides
8
Knowledge Check10 questions · pass mark 8/10
Quiz
Knowledge Check
Q1: Under Priya's 'collect once, audit forever' rule, which of these is NOT one of the four layers captured for every privileged account?
The JML linkage: the named owner and their joiner-mover-leaver status
The access patterns: when, where from, how often and for what
The account's purchase cost and licence renewal date
The password reality: actual age, rotation history and whether it is vaulted
Q2: What is Priya's test for whether an identity belongs in the privileged access inventory?
Can it authenticate, and can it act?
Is it listed in the HR system?
Is it labelled as artificial intelligence?
Was it approved through a change request?
Q3: What role does artificial intelligence play in Priya's discovery work?
It replaces the analyst and the business owner
It automatically revokes suspicious access without review
It is only useful once the programme is fully mature
It finds, prioritises and explains findings, but people decide who holds privilege
Q4: Why did user and group permission reviews become a key source for spotting hidden privilege?
They list every device on the domain
They reveal inherited permissions through group membership: privilege nobody granted directly, so nobody remembers it
They record every command a user executes
They replace the need for access reviews
Q5: In the Attacker's Lens scene, why does the module treat the identity-verification (password and MFA reset) process as privileged access?
Because help-desk staff are always domain administrators
Because reset processes are covered by GDPR
Because whoever can reset a privileged user's password or re-enrol their MFA effectively holds privileged access, and synthetic voice makes a phone call weak proof of identity
Because reset requests are logged in the SIEM
Q6: Priya scores each account on its reach, its level of privilege and its state. What fourth question does she add when the holder isn't a person?
How much can it do without asking?
Which vendor built it?
How much did it cost to deploy?
Is it hosted in the cloud?
Q7: What is the main lesson of the Adobe (2013) case study?
SIEM tools are unnecessary if you have antivirus
Zero-day exploits cannot be detected
Logs should be deleted regularly to reduce noise
A SIEM is only as good as its configuration and the trained people interpreting its most significant alerts
Q8: How did attackers get the credentials used in the Uber breach described in this module?
From a former employee's account that was never disabled
From login credentials for Uber's cloud storage embedded in code on GitHub
Through a brute-force attack on the VPN
Through a compromised heating and air-conditioning contractor
Q9: When interviewing privileged users, what caveat does the module give?
Only interview senior managers
Never let interviewees know why they are being asked
Corroborate what people tell you against logs and records, because memory is a source, not an oracle
Treat interview answers as more reliable than any scan
Q10: What does the OPM case study show about risk categorisation?
Contractors should never be given accounts
Risk categorisation matters only for regulatory reporting
All accounts should receive equal monitoring
An uncategorised high-risk account gets the same limited attention as everything else; a list without risk ratings is a phone book
Requirements
Completion of Module 2 (recommended)
Basic understanding of IT administration or security concepts
Target audience: security and IT professionals, PAM practitioners and programme leads
No vendor-specific tool knowledge required — this module is vendor-neutral