Soru

Zorluk: OrtaZero Trust Architecture Principles

A security architect is implementing NIST SP 800-207 Zero Trust Architecture (ZTA) logical components within an enterprise hybrid network. Match each Zero Trust logical component on the left with its correct operational responsibility on the right.

  • Policy Engine (PE)Evaluates enterprise security policies and contextual risk signals to render the ultimate decision to grant or deny resource access.
  • Policy Administrator (PA)Issues control commands to initiate, configure, or terminate the communication session between the user subject and enterprise resource.
  • Policy Enforcement Point (PEP)Intercepts, monitors, and applies control plane instructions directly to active data plane traffic sessions.

Cevap

Policy Engine matches evaluating policy rules and rendering access decisions; Policy Administrator matches issuing control signals to open or close session connections; Policy Enforcement Point matches intercepting and enforcing access controls on data plane traffic.
In NIST SP 800-207 Zero Trust Architecture, responsibilities are split across control and data planes: the Policy Engine renders access decisions based on contextual risk and policy; the Policy Administrator handles control channel signaling to establish or break connections; and the Policy Enforcement Point acts as the data plane gatekeeper enforcing those decisions on live session traffic.

Adım Adım Çözüm

1
Identify the primary role of the Policy Engine (PE)
The Policy Engine acts as the decision-making authority within the Zero Trust control plane.
Under NIST SP 800-207, the Policy Engine uses trust algorithms and contextual input to determine whether access should be granted.
2
Identify the primary role of the Policy Administrator (PA)
The Policy Administrator manages session state and control plane commands.
Once the Policy Engine renders a decision, the Policy Administrator signals the underlying gateway or client components to open or close the connection.
3
Identify the primary role of the Policy Enforcement Point (PEP)
The Policy Enforcement Point functions as the data plane gateway.
The Policy Enforcement Point sits directly in the communication channel to monitor, allow, or drop connection traffic based on instructions from the Policy Administrator.

Anahtar Kavram

Zero Trust Control Plane vs. Data Plane Component Functions
Tahmini Süre:1m 30s
Bu soruyu puanla