Cisco CCNP Security Core (SCOR) 350-701Endpoint Security and Secure Network AccessEasy

A security engineer is designing a secure network access solution for a campus network. The design requires that all endpoints, including corporate laptops, personal mobile devices, and IoT sensors, are authenticated and authorized before gaining access to network resources. Which network access control (NAC) component is primarily responsible for evaluating the endpoint's compliance with security policies and assigning appropriate network access privileges?

  1. AAuthenticator
  2. BSupplicant
  3. CPolicy Enforcement Point (PEP)
  4. DPolicy Decision Point (PDP)
Show answer & explanation

Correct answer: D. Policy Decision Point (PDP)

The Policy Decision Point (PDP) is the component within a NAC architecture that evaluates the security policies against the supplicant's attributes and makes the decision on whether to grant or deny access, and what level of access to provide.

Why the other options are wrong

  • A. The Authenticator (e.g., a switch or WLC) enforces the policy, but does not make the decision.
  • B. The Supplicant is the endpoint requesting access, not a decision-making component.
  • C. The Policy Enforcement Point (PEP) enforces the policy decision made by the PDP, but does not make the decision itself.

Policy Decision Point (PDP)

A component in a Network Access Control (NAC) system responsible for evaluating security policies and making access decisions for connecting endpoints.

  • Evaluates endpoint attributes against defined policies.
  • Determines the appropriate level of network access.
  • Communicates decisions to the Policy Enforcement Point (PEP).

Memory trick: Supplicants supplicate, Authenticator authenticates, PDP decides, PEP enforces.

More Endpoint Security and Secure Network Access questions