Study. uk . com
  1. Home
  2. All questions
  3. Question 201

CISSP study material · question 201 of 500

What does the policy engine feed into its trust algorithm before granting, denying or revoking access?

  1. Enterprise policy together with external inputs such as diagnostics systems and threat intelligence.
  2. The organisation's risk tolerance statement and its target profile.
  3. Only the enforcement point's record of previous sessions.
  4. Only the subject's group memberships as held in the directory.
Show the answer

Answer: A. Enterprise policy together with external inputs such as diagnostics systems and threat intelligence.

The policy engine uses enterprise policy plus input from external sources such as continuous diagnostics systems and threat intelligence services as input to the trust algorithm.

Source: NIST SP 800-207 (NIST) — SP 800-207 > 3 Logical Components, Policy engine

Challenge yourself on this topic → Study as cards