In a zero-trust design discussion, which pairing correctly places the policy decision and the policy enforcement roles?
Select an answer to reveal the explanation.
Short Explanation
Picture a bouncer with a radio: the brain on the radio (policy engine) says yes or no, and the arm at the door (enforcement point) actually blocks or lets traffic through. Decision sits on the control plane; enforcement sits on the data path.
Full Explanation
SY0-701 zero-trust framing distinguishes control-plane decision functions from data-plane enforcement. A policy engine (or policy decision point) evaluates access; a policy enforcement point applies allow/deny on the data path. Mixing deception technology, accounting alone, or physical bollards into those roles misunderstands the model. Candidates need Security+ depth on this split, not niche ZTNA product configuration.