The question this module answers
How do you know, rather than believe, that your PAM programme actually works?
Eight months into the programme, Layla books Internal Audit. Elena works through seven levels of review questions, from policy and discovery to DevOps and break glass. At each level the person who built it answers with evidence, not assurances. Her verdict: 'Not a tool. Not a project. A programme.'
Knowledge Check
Q1: Which of these is NOT one of the five purposes of a PAM review and maturity model named in Module 9?
Enhanced security
Regulatory compliance
Proactive risk management
Reducing software licence costs
Q2: At Level 1 (Policy & Process), what does Elena say the real question is?
Whether the policy is longer than competitors'
Not whether a policy exists, but whether it lives
Whether the policy was written by a consultant
Whether the policy mentions a specific vendor
Q3: Under which review level would you ask how orphaned or dormant privileged accounts are identified and managed?
Asset & Account Discovery
Technology Integration
DevOps
Break Glass
Q4: What does Elena's favourite 'role-creep' question look for?
Roles with too few permissions to do their job
Roles that have accumulated too many privileges over time
Users who have changed their passwords recently
Roles that are not yet connected to the SIEM
Q5: Why does the Level 4 (Monitoring & Auditing) review open with training questions?
Training is cheaper than monitoring
Regulators only ask about training
You cannot audit behaviour you haven't first educated
Monitoring tools require a training licence
Q6: At Level 5 (Technology Integration), what does integration with a CASB let the PAM solution do?
Monitor and control privileged access to cloud resources
Replace the need for MFA
Scan code for vulnerabilities in CI/CD pipelines
Generate employee payroll reports
Q7: What does Kenji's Level 6 (DevOps) evidence show?
DevOps was exempted from PAM to protect speed
Credential rotation remains manual in the pipeline
PAM integration slowed deployments significantly
Credential rotation is automated in CI/CD and machine identities are vaulted, and speed didn't drop but attack surface did
Q8: According to the Level 7 questions, how should least privilege be maintained even in an emergency?
Emergency accounts should hold full domain admin rights permanently
By using time-based or activity-based restrictions and predefined access levels for the type of emergency
By sharing one emergency password with the whole IT team
Least privilege is suspended during emergencies
Q9: What evidence did Ahmed present for Level 7 (Break Glass)?
A single annual tabletop exercise
A policy document awaiting approval
Quarterly drills, some unannounced, with full audit logs, automatic revocation and a post-incident review for each
A list of emergency passwords kept in a safe
Q10: Which sequence correctly lists the seven review levels in Module 9?
Policy & Process, Asset & Account Discovery, Access Controls, Monitoring & Auditing, Technology Integration, DevOps, Break Glass
Asset & Account Discovery, Policy & Process, Monitoring & Auditing, Access Controls, DevOps, Technology Integration, Break Glass
Policy & Process, Access Controls, Asset & Account Discovery, Technology Integration, Monitoring & Auditing, Break Glass, DevOps
Break Glass, DevOps, Technology Integration, Monitoring & Auditing, Access Controls, Asset & Account Discovery, Policy & Process
Requirements
Completion of Module 8 (recommended)
Basic understanding of IT administration or security concepts
Target audience: security and IT professionals, PAM practitioners and programme leads
No vendor-specific tool knowledge required — this module is vendor-neutral