Soru

Zorluk: OrtaIdentity and Access Management Architecture

An enterprise security architect is designing an Identity and Access Management (IAM) architecture for a hybrid enterprise environment. To align with modern Zero Trust principles, the system must evaluate real-time context—such as user risk score, device compliance state, and access location—before granting access to sensitive cloud databases, rather than trusting users based on network location. Which architectural component in this framework is directly responsible for evaluating these dynamic context attributes against enterprise security policies to render an access decision?

  1. Policy Decision Point (PDP)Cevap
  2. B
    Policy Enforcement Point (PEP)
  3. C
    Perimeter Next-Generation Firewall (NGFW)
  4. D
    Centralized LDAP Identity Repository

Cevap

Policy Decision Point (PDP)
In Zero Trust identity architectures, the Policy Decision Point (PDP) examines subject attributes, requested resources, and real-time environmental context against security policies to produce authorization decisions.

Adım Adım Çözüm

1
Identify the core requirement in the scenario.
The requirement specifies evaluating dynamic context (device posture, user risk score, location) against security policies to make authorization decisions.
Distinguishing policy evaluation logic from policy enforcement and credential storage isolates the responsible component.
2
Map the requirement to standard Zero Trust IAM architectural roles.
The component that executes policy rules to yield a grant/deny outcome is the Policy Decision Point (PDP).
In Zero Trust architecture, the PDP acts as the centralized engine responsible for rendering access decisions before passing them to enforcement mechanisms.

Anahtar Kavram

Zero Trust IAM Architecture and Policy Decision Points (PDP)
Bu soruyu puanla