exam questions

Exam CSCP All Questions

View all questions & answers for the CSCP exam

Exam SC-100 topic 4 question 27 discussion

Actual exam question from APICS's CSCP
Question #: 27
Topic #: 1
[All CSCP Questions]

You have a Microsoft 365 subscription and an Azure subscription. Microsoft 365 Defender and Microsoft Defender for Cloud are enabled.

The Azure subscription contains 50 virtual machines. Each virtual machine runs different applications on Windows Server 2019.

You need to recommend a solution to ensure that only authorized applications can run on the virtual machines. If an unauthorized application attempts to run or be installed, the application must be blocked automatically until an administrator authorizes the application.

Which security control should you recommend?

  • A. Azure AD Conditional Access App Control policies
  • B. Azure Security Benchmark compliance controls in Defender for Cloud
  • C. app protection policies in Microsoft Endpoint Manager
  • D. application control policies in Microsoft Defender for Endpoint
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
zellck
5 months, 1 week ago
Same as Question 23. https://www.examtopics.com/discussions/microsoft/view/99695-exam-sc-100-topic-4-question-23-discussion
upvoted 2 times
...
zellck
5 months, 1 week ago
Selected Answer: D
D is the answer. https://learn.microsoft.com/en-us/mem/configmgr/protect/deploy-use/use-device-guard-with-configuration-manager prevents malicious code from running by ensuring that only approved code, that you know, can be run. Application Control is a software-based security layer that enforces an explicit list of software that is allowed to run on a PC. On its own, Application Control doesn't have any hardware or firmware prerequisites. Application Control policies deployed with Configuration Manager enable a policy on devices in targeted collections that meet the minimum Windows version and SKU requirements outlined in this article. Optionally, hypervisor-based protection of Application Control policies deployed through Configuration Manager can be enabled through group policy on capable hardware.
upvoted 1 times
Nail
4 months, 3 weeks ago
why do you have a link for device guard? That is protecting you from unsafe websites, not apps.
upvoted 1 times
Nail
4 months, 3 weeks ago
My bad, I was thinking of application guard. device guard is the old name for WDAC.
upvoted 1 times
...
...
...
CarisB
5 months, 4 weeks ago
Selected Answer: D
Windows Defender Application Control (WDAC) seems better, but I go for D
upvoted 3 times
Nail
4 months, 3 weeks ago
WDAC and app control policies in MDE are one and the same.
upvoted 2 times
...
...
MaciekMT
6 months ago
from ChatGPT: Based on the requirements of ensuring that only authorized applications can run on the virtual machines, and that an unauthorized application is blocked automatically until an administrator authorizes it, the recommended security control to implement is application control policies in Microsoft Defender for Endpoint. Application control policies in Microsoft Defender for Endpoint provide a way to prevent the execution of malicious and unauthorized applications on Windows 10 and Windows Server 2019 machines. Application control policies can be used to block all unknown applications or allow only trusted applications to run. Using application control policies, you can create policies that restrict application execution to a specific set of approved applications. When an unknown application attempts to run, it will be blocked until the administrator approves it. Therefore, the correct answer is D) application control policies in Microsoft Defender for Endpoint.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago