Soru

Zorluk: ZorZero Trust Architecture Principles

An enterprise organization is establishing a micro-segmented hybrid environment based on Zero Trust Architecture (ZTA) control plane and data plane principles. Match each logical Zero Trust component on the left with its correct operational responsibility on the right.

  • Policy Engine (PE)Evaluates contextual signals, trust criteria, and security rules to determine whether access to a requested resource should be granted, denied, or revoked.
  • Policy Administrator (PA)Executes policy decisions by issuing dynamic session credentials and sending signals to set up or tear down encrypted communication paths.
  • Policy Enforcement Point (PEP)Functions in the data plane to directly inspect, route, initiate, or terminate network connections between client subjects and enterprise workloads.

Cevap

Policy Engine (PE) matches with evaluating contextual signals and determining access decisions; Policy Administrator (PA) matches with issuing dynamic credentials and signaling path setups; Policy Enforcement Point (PEP) matches with operating in the data plane to inspect traffic and enforce access boundaries.
Under NIST SP 800-207, Zero Trust architecture divides functions between the control plane and data plane. The Policy Engine evaluates trust inputs to decide access. The Policy Administrator communicates control decisions by managing credentials and signaling gateways. The Policy Enforcement Point sits on the data plane to enforce session bounds.

Adım Adım Çözüm

1
Analyze the core function of the Policy Engine (PE)
Identify that the Policy Engine is purely analytical and rule-based, responsible for evaluating trust signals to reach an access decision.
Control plane separation isolates decision logic within the Policy Engine component.
2
Analyze the core function of the Policy Administrator (PA)
Identify that the Policy Administrator acts on the Policy Engine decision by generating required short-lived tokens or keys and signaling the data plane.
The Policy Administrator serves as the control plane actuator between decision logic and physical gateway mechanisms.
3
Analyze the core function of the Policy Enforcement Point (PEP)
Identify that the Policy Enforcement Point directly handles payload traffic on the data plane to permit, restrict, or break session connections.
Data plane enforcement requires inline monitoring and access control mechanisms.

Anahtar Kavram

Logical Components of Zero Trust Architecture (Policy Engine, Policy Administrator, Policy Enforcement Point)
Tahmini Süre:2m 0s
Bu soruyu puanla