Privileged account
An account with rights beyond an ordinary user's, able to change security settings, manage other accounts or reach sensitive data, such as administrator, root and many service accounts.
A privileged account is one whose rights let it perform security-relevant functions that ordinary users cannot, such as changing system configuration, creating or modifying accounts, managing keys, or reading data outside normal job needs. NIST SP 800-53 Rev. 5 gives key management, account management, database administration, system and network administration, and web administration as examples of privileged roles (AC-2(7) discussion), and notes that privileged accounts include super user accounts (AC-6(5) discussion). Local and domain administrator accounts, root, emergency break-glass accounts and many service accounts fall into this class.
Because a compromised privileged account can do far more damage than an ordinary one, the controls around it are stricter. AC-6(5) restricts privileged accounts to defined personnel or roles, and AC-6(2) requires their holders to use a non-privileged account when doing work that is not security-related, such as reading email or browsing. Other common controls are phishing-resistant authentication, vaulted credentials, time-bound elevation, logging of privileged functions, and more frequent access review. Managing these accounts as a group is the work of privileged access management.
Exam relevance: a scenario is likely to describe an administrator reading email or browsing the web from an administrative account. Candidates are expected to recommend separate privileged and standard accounts, and to treat privileged accounts as the first place for stronger authentication and closer review.