Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureMedium
A large pharmaceutical company is implementing a Zero Trust strategy. They have a complex network infrastructure with numerous internal applications and services, some of which are legacy and lack modern authorization mechanisms. The company needs to enforce granular access policies to these internal resources based on user identity, device posture, and application context, without modifying the legacy applications themselves. Which Zero Trust component acts as the critical enforcement point to achieve this?
- APolicy Enforcement Point (PEP)
- BPolicy Information Point (PIP)
- CPolicy Administration Point (PAP)
- DPolicy Decision Point (PDP)
Show answer & explanationAnswer & explanation
Correct answer: A. Policy Enforcement Point (PEP)
The Policy Enforcement Point (PEP) is the component that actually grants, denies, or revokes access to a resource based on the decisions made by the Policy Decision Point (PDP). It sits in the data path, intercepting access requests and enforcing the determined policy without requiring changes to the applications themselves, which is crucial for legacy systems in a Zero Trust environment.
Why the other options are wrong
- B. PIP provides attributes or data required by the PDP to make a decision, it does not enforce policies.
- C. PAP is used for creating, managing, and storing security policies, not for enforcing them.
- D. PDP evaluates policies and attributes to make an access decision, but it does not directly enforce it.
Policy Enforcement Point (PEP)
A Zero Trust component that sits in the path to a resource, intercepting access requests and enforcing the access decision made by the Policy Decision Point.
- Grants, denies, or revokes access.
- Acts as the 'gatekeeper' to resources.
- Crucial for enforcing policies without modifying applications.
Memory trick: PEP: The Gatekeeper That Enforces Policy.