Cisco CCNP Security Core (SCOR) 350-701Endpoint Security and Secure Network AccessEasy
A security architect is designing a secure network access solution for a large university campus. The solution must support a diverse range of devices, including student laptops, faculty desktops, IoT devices in labs, and guest mobile phones. The architect wants to ensure that each device type receives appropriate network access policies based on its identity and security posture. Which component of a secure network access solution is primarily responsible for evaluating device identity and health against predefined policies to grant or deny access?
- ASupplicant
- BAuthenticator
- CPolicy Enforcement Point (PEP)
- DPolicy Decision Point (PDP)
Show answer & explanationAnswer & explanation
Correct answer: D. Policy Decision Point (PDP)
The Policy Decision Point (PDP) is the component that evaluates the authentication and authorization requests against defined policies. It determines whether a supplicant should be granted access and what level of access it should receive.
Why the other options are wrong
- A. The supplicant is the end device requesting access, it does not make policy decisions.
- B. The authenticator mediates access between the supplicant and the authentication server, but doesn't decide policy.
- C. The PEP enforces the decision made by the PDP, it does not make the decision itself.
Policy Decision Point (PDP)
The component in a secure network access architecture responsible for evaluating requests against defined policies and making access control decisions.
- Evaluates device identity and health.
- Determines access rights based on policies.
- Communicates decisions to the Policy Enforcement Point (PEP).
Memory trick: Supplicant asks, Authenticator passes, PDP decides, PEP enforces.