StudyToCert

All certifications / CC / Lessons

ISC2 Certified in Cybersecurity 2026 outline · Domain 3: Identity & access management concepts

Privileged access management and separate admin accounts

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Some accounts can do far more than others. Administrator and root accounts can install software, change security settings, create users, read any file and erase logs. Service accounts may run critical applications with broad rights. These are privileged accounts, and attackers target them because controlling one often means controlling the whole environment. Privileged access management (PAM) is the set of practices and tools that protect, limit and monitor these accounts.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 5 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CC for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CC study plan