Soru

Zorluk: OrtaIdentity and Access Management Architecture

Match each Identity and Access Management (IAM) architectural component to its primary role within an access evaluation control framework.

  • Policy Decision Point (PDP)Evaluates access requests against security rules to issue authorization decisions.
  • Policy Enforcement Point (PEP)Intercepts user requests and enforces authorization decisions by permitting or blocking traffic.
  • Policy Information Point (PIP)Retrieves external contextual attributes, such as device status and location, to inform access evaluations.
  • Policy Administration Point (PAP)Provides the management interface used to create, test, and store access control policy definitions.

Cevap

Policy Decision Point (PDP) matches authorization evaluation; Policy Enforcement Point (PEP) matches traffic interception and enforcement; Policy Information Point (PIP) matches contextual attribute retrieval; Policy Administration Point (PAP) matches policy creation and management.
In modern access control and Zero Trust architectures, access evaluation is divided across specialized functional entities. The Policy Decision Point (PDP) evaluates request parameters against access policies. The Policy Enforcement Point (PEP) enforces the resulting decision at network or application boundary gates. The Policy Information Point (PIP) supplies requisite contextual attributes (such as user attributes or threat telemetry) to the PDP. The Policy Administration Point (PAP) acts as the governance interface for policy creation and maintenance.

Adım Adım Çözüm

1
Identify the component that computes authorization logic.
Policy Decision Point (PDP) is paired with evaluating access requests to issue decisions.
The PDP evaluates rules against subject and resource attributes to generate a permit or deny outcome.
2
Identify the gateway component sitting inline with traffic.
Policy Enforcement Point (PEP) is paired with intercepting requests and enforcing decisions.
The PEP acts as a gatekeeper that blocks or permits user access based on the PDP's determination.
3
Identify the entity responsible for supplying external context.
Policy Information Point (PIP) is paired with retrieving contextual attributes.
The PIP feeds environmental variables, user group memberships, and device compliance context into the evaluation engine.
4
Identify the administration interface for policy lifecycle management.
Policy Administration Point (PAP) is paired with creating and storing policy rules.
The PAP is the administrative system where security policies are authored and published.

Anahtar Kavram

IAM Architecture Control Points (PDP, PEP, PIP, PAP)
Bu soruyu puanla