CompTIA Security+ (SY0-701)General Security ConceptsMedium
A company is implementing a zero trust architecture. Which component is responsible for evaluating a request against policy and deciding whether to grant or deny access?
- AData plane
- BSubject
- CPolicy decision point
- DPolicy enforcement point
Show answer & explanationAnswer & explanation
Correct answer: C. Policy decision point
In zero trust architecture, the policy decision point (PDP) evaluates access requests against defined policies and makes the grant/deny decision, which the policy enforcement point then carries out.
Why the other options are wrong
- A. The data plane carries the actual traffic once access is granted.
- B. The subject is the user or device requesting access, not the decision-maker.
- D. The policy enforcement point implements the decision but does not make it.
Policy Decision Point (PDP)
In zero trust architecture, the control-plane component that evaluates access requests against policy and decides whether to allow them.
- Works with policy enforcement point (PEP)
- Part of the control plane, not data plane
- Central to NIST zero trust model (SP 800-207)
Memory trick: Decide first (PDP), then enforce (PEP)