Study. uk . com
  1. Home
  2. All questions
  3. Question 199

CISSP study material · question 199 of 500

An architect asks how the policy enforcement point may be realised in practice under SP 800-207. Which description is correct?

  1. Only as a network firewall placed at the enterprise perimeter.
  2. As a component of the policy engine, which cannot be separated from it.
  3. Only as an agent installed on the resource itself.
  4. As a client-side agent plus a gateway in front of the resource, or as a single portal acting as gatekeeper.
Show the answer

Answer: D. As a client-side agent plus a gateway in front of the resource, or as a single portal acting as gatekeeper.

The enforcement point is one logical component but may be split into a client-side agent and a resource-side gateway, or implemented as a single portal component.

Source: NIST SP 800-207 (NIST) — SP 800-207 > 3 Logical Components, Policy enforcement point

Challenge yourself on this topic → Study as cards