SY0-701 exam dumps

SY0-701 practice question 18 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 18

Single answer

A company is replacing its flat internal network with a Zero Trust architecture after an attacker used a compromised employee laptop to move laterally from a user VLAN to a finance application. The security team wants access decisions to consider user role, device health, and current risk signals before each connection is established. They also want the enforcement point to block or allow the session based on centrally defined policy, without relying on the old assumption that systems on the internal network are trusted. Which component should make the access decision and instruct the enforcement point accordingly?

  1. A

    Policy Engine in the control plane

  2. B

    Data plane switch handling east-west traffic

  3. C

    Subject/System initiating the connection

  4. D

    Implicit trust zone for internal corporate devices

Show answer and explanation

Correct answer: A

Explanation

This question tests the candidate's ability to apply Zero Trust concepts to a realistic lateral-movement problem. The key requirement is centralized, context-aware, policy-driven access control that evaluates adaptive identity factors such as role, device health, and risk signals for each request. In Zero Trust reference architectures, this decision function is performed by the Policy Engine in the control plane. The Policy Administrator uses that decision to set up or deny the connection, and the Policy Enforcement Point enforces the decision on the session or traffic path. The data plane is where the permitted traffic flows, but it is not the primary policy decision-maker. A major Zero Trust principle, emphasized in NIST SP 800-207, is to eliminate broad implicit trust based on network location and instead continuously verify the subject/system and limit access to reduce the threat scope.

  • A. Correct.

    Correct. In Zero Trust, the Policy Engine is the decision-making component in the control plane. It evaluates context such as identity, device posture, requested resource, and risk/adaptive signals to determine whether access should be granted. It works with policy-driven access control and provides the decision that the environment uses to enforce access. In common Zero Trust reference models, the Policy Administrator then helps establish, configure, or terminate the session based on the Policy Engine's decision, and the Policy Enforcement Point enforces that decision on the traffic flow.

  • B. Incorrect.

    Incorrect. The data plane carries the actual application or network traffic after policy is applied; it is not the component that should make the centralized trust decision. A switch or other forwarding element may participate in enforcement, but in a Zero Trust model the decision logic belongs in the control plane, not in a generic forwarding device deciding policy on its own.

  • C. Incorrect.

    Incorrect. The subject/system is the user, device, application, or workload requesting access. It provides attributes used in the decision, but it should not be trusted to determine its own access level. Letting the requester decide would conflict with Zero Trust principles and would weaken policy-driven access control.

  • D. Incorrect.

    Incorrect. Zero Trust specifically reduces or removes reliance on implicit trust zones such as 'internal network equals trusted.' Treating internal corporate devices as a trusted zone is the legacy approach that enabled lateral movement in the scenario. Threat scope reduction is achieved by continuously evaluating trust per request rather than granting broad trust based on location.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam