PIM role settings should require MFA on activation for Security Administrator. Where is this enforced?
Select an answer to reveal the explanation.
Short Explanation and Infographic
PIM role settings demand MFA at activation — extra proof when privilege turns on.
Full explanation below image
Full Explanation
Correct Answer — B
PIM role settings include MFA on activation, approval, duration, and justification. Documents and emoji don't enforce. Permanent disable is not MFA-on-activation.
Exam tip: MFA when elevating → PIM role setting.