CompTIA SecurityX (CAS-005)Security ArchitectureEasy
A security architect is designing a Zero Trust architecture for an enterprise. The goal is to ensure that all access requests, regardless of their origin (internal or external), are explicitly verified before granting access to resources. Which component is primarily responsible for making the decision to grant or deny access based on established policies?
- ATrust Algorithm.
- BPolicy Decision Point (PDP).
- CPolicy Information Point (PIP).
- DPolicy Enforcement Point (PEP).
Show answer & explanationAnswer & explanation
Correct answer: B. Policy Decision Point (PDP).
In a Zero Trust architecture, the Policy Decision Point (PDP) is the component that evaluates access requests against defined policies and makes the ultimate decision to grant, deny, or revoke access to a resource.
Why the other options are wrong
- A. A Trust Algorithm is a conceptual model or method for assessing trust, not a specific component in the Zero Trust architecture.
- C. The PIP gathers additional context and attributes needed by the PDP for its decision, but doesn't make the decision itself.
- D. The PEP enforces the decision made by the PDP, it does not make the decision itself.
Zero Trust Policy Decision Point (PDP)
In a Zero Trust architecture, the Policy Decision Point (PDP) is the logical component responsible for making the final decision to grant or deny access to a resource based on existing access policies and contextual information.
- Evaluates access requests against policies.
- Makes the 'grant' or 'deny' decision.
- Communicates its decision to the Policy Enforcement Point (PEP).
Memory trick: The PDP is the 'Judge' of the Zero Trust court, deciding who gets in.