Cisco CCNP Security Core (SCOR) 350-701Endpoint Security and Secure Network AccessMedium

A security architect is designing a secure network access solution for a large enterprise with diverse user roles and device types. The solution must provide granular access control based on user identity, device posture, and application being accessed. Which component is primarily responsible for evaluating the authorization policies and making access decisions in such a system?

  1. APolicy Information Point (PIP)
  2. BPolicy Decision Point (PDP)
  3. CPolicy Enforcement Point (PEP)
  4. DPolicy Administration Point (PAP)
Show answer & explanation

Correct answer: B. Policy Decision Point (PDP)

The Policy Decision Point (PDP) is the component within a secure network access architecture that evaluates authorization policies and makes the ultimate decision on whether to grant or deny access. It receives requests from the PEP and consults the PIP for necessary attributes.

Why the other options are wrong

  • A. The Policy Information Point (PIP) acts as a source of attributes or information needed by the PDP to make its decisions, but it does not make the decision itself.
  • C. The Policy Enforcement Point (PEP) is responsible for enforcing the access decision made by the PDP, not making the decision itself.
  • D. The Policy Administration Point (PAP) is used to create, manage, and store policies, not to make real-time access decisions.

Policy Decision Point (PDP)

The Policy Decision Point (PDP) is a component in a policy-based access control system that evaluates authorization policies and makes the access decision to grant or deny a request.

  • Receives access requests from the Policy Enforcement Point (PEP).
  • Consults the Policy Information Point (PIP) for necessary attributes.
  • Outputs an access decision (permit/deny) back to the PEP.

Memory trick: Policies Decide Permissions for Every User.

More Endpoint Security and Secure Network Access questions