Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureHard

A large pharmaceutical company is implementing a Zero Trust strategy. They have a complex environment with numerous applications and resources, each with specific access requirements. To enforce granular access control policies based on user identity, device compliance, location, and application sensitivity, which component is primarily responsible for performing the access decision and granting or denying access in real-time?

  1. APolicy Enforcement Point (PEP)
  2. BPolicy Administration Point (PAP)
  3. CPolicy Information Point (PIP)
  4. DPolicy Decision Point (PDP)
Show answer & explanation

Correct answer: A. Policy Enforcement Point (PEP)

The Policy Enforcement Point (PEP) is the component that actually performs the access decision, granting or denying access to a resource based on the policy decision received from the Policy Decision Point (PDP). It sits in the data path and enforces the access control policies.

Why the other options are wrong

  • B. PAP is used for creating, managing, and storing policies.
  • C. PIP provides attributes or data needed by the PDP for making a decision.
  • D. PDP evaluates the request against policies and makes the access decision, but doesn't enforce it.

Policy Enforcement Point (PEP)

The component in a Zero Trust architecture responsible for enforcing the access decision (grant or deny) made by the Policy Decision Point (PDP). It sits in the data path between the subject and the resource.

  • Actual point where access is granted or denied.
  • Receives decisions from the PDP.
  • Can be a firewall, API gateway, proxy, or identity provider.
  • Critical for real-time policy enforcement.

Memory trick: PEP is the 'Police' at the door.

More Design a Zero Trust strategy and architecture questions