CompTIA Security+ (SY0-701)General Security ConceptsMedium
In a zero trust architecture, a user's request to access a financial application is evaluated by policy logic and then a decision must actually be carried out on the network, such as opening or blocking a session. Which component performs this enforcement action?
- APolicy Enforcement Point
- BPolicy Decision Point
- CPolicy Administrator
- DTrust Broker
Show answer & explanationAnswer & explanation
Correct answer: A. Policy Enforcement Point
The Policy Enforcement Point (PEP) sits inline between the subject and resource and carries out the decision made by the Policy Decision Point, such as granting or denying access.
Why the other options are wrong
- B. The PDP evaluates policy and makes the decision but does not directly enforce it on the network.
- C. Policy Administrator is a sub-component of the PDP responsible for establishing/severing the communication path, not the standard NIST term for this enforcement role.
- D. Trust Broker is not a standard zero trust architecture component defined by NIST.
Policy Enforcement Point (PEP)
The zero trust component that enforces the access decision by allowing, denying, or terminating a connection between subject and resource.
- Works together with the Policy Decision Point (PDP)
- Sits inline in the data path
- Defined in NIST SP 800-207 zero trust architecture
Memory trick: PDP decides, PEP does.