CompTIA Security+ (SY0-701)General Security ConceptsMedium

A company is implementing a zero trust architecture. Which component is responsible for evaluating a request against policy and deciding whether to grant or deny access?

  1. AData plane
  2. BSubject
  3. CPolicy decision point
  4. DPolicy enforcement point
Show answer & explanation

Correct answer: C. Policy decision point

In zero trust architecture, the policy decision point (PDP) evaluates access requests against defined policies and makes the grant/deny decision, which the policy enforcement point then carries out.

Why the other options are wrong

  • A. The data plane carries the actual traffic once access is granted.
  • B. The subject is the user or device requesting access, not the decision-maker.
  • D. The policy enforcement point implements the decision but does not make it.

Policy Decision Point (PDP)

In zero trust architecture, the control-plane component that evaluates access requests against policy and decides whether to allow them.

  • Works with policy enforcement point (PEP)
  • Part of the control plane, not data plane
  • Central to NIST zero trust model (SP 800-207)

Memory trick: Decide first (PDP), then enforce (PEP)

More General Security Concepts questions