Certified Information Systems Security Professional CISSP · Free Practice Question Medium

Question 52

A financial institution has implemented a Zero-Trust Architecture to secure its network infrastructure. In this model, which component is PRIMARILY responsible for making access control decisions by evaluating requests based on risk and security policies before granting or denying access?
  • A Access Control List.
  • B Policy Enforcement Point.
  • C Policy Engine.
  • D Policy Administrator.
Reveal correct answer

Correct answer: C

Explanation

OBJ. 3.1 - In a Zero-Trust Architecture, the Policy Engine makes real-time access control decisions based on identity, device health, and contextual risk factors. The Policy Enforcement Point (PEP) applies these decisions but does not make them. The Policy Administrator manages security configurations but does not evaluate risk dynamically. ACLs are static lists and do not provide real-time security decisions. The Policy Engine ensures that each access request is verified before granting access. For support or reporting issues, include Question ID: 67d9676822f03b67bc784a01 in your ticket. Thank you.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need