exam questions

Exam MD-101 All Questions

View all questions & answers for the MD-101 exam

Exam MD-101 topic 1 question 31 discussion

Actual exam question from Microsoft's MD-101
Question #: 31
Topic #: 1
[All MD-101 Questions]

Note: The question is included in a number of questions that depicts the identical set-up. However, every question has a distinctive result. Establish if the solution satisfies the requirements.
Your company has a number of Windows 10 Microsoft Azure Active Directory (Azure AD) joined workstations. These workstations have been enrolled in Microsoft
Intune.
You have been tasked with making sure that the workstations are only able to run applications that you have explicitly permitted.
Solution: You make use of Windows Defender Application Guard.
Does the solution meet the goal?

  • A. Yes
  • B. No
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
nyashac
Highly Voted 3 years, 9 months ago
wrong answer windows defender application control https://docs.microsoft.com/en-us/mem/configmgr/protect/deploy-use/use-device-guard-with-configuration-manager#:~:text=Windows%20Defender%20Application%20Control%20is,malware%20and%20other%20untrusted%20software.&text=Windows%20Defender%20Application%20Control%20is%20a%20software%2Dbased%20security%20layer,to%20run%20on%20a%20PC.
upvoted 22 times
RodrigoT
3 years, 1 month ago
And the link provided is also broken (must remove an space character). This is the right one: https://docs.microsoft.com/en-us/windows/security/threat-protection/device-guard/introduction-to-device-guard-virtualization-based-security-and-windows-defender-application-control that says: "we no longer use the Device Guard brand". So it used to be the right answer, but the test was updated on November 24, so beware. Now it's: Windows Defender Application CONTROL. Check for yourself: https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/select-types-of-rules-to-create Windows Defender Application Control (WDAC) is used to restrict devices to run only approved apps.
upvoted 2 times
RodrigoT
3 years ago
Nowadays Windows Defender Application Guard is only for Edge and Office. It opens untrusted sites and files in an isolated Hyper-V-enabled container. This container isolation means that if the untrusted site or file turns out to be malicious, the host device is protected, and the attacker can't get to your enterprise data. https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-application-guard/md-app-guard-overview
upvoted 5 times
...
...
...
justabasicuser
Highly Voted 3 years, 9 months ago
Its no as it should be Windows Defender Application Control.
upvoted 11 times
...
Meebler
Most Recent 2 years, 4 months ago
B, Using Windows Defender Application Guard alone is not sufficient to ensure that the workstations are only able to run applications that you have explicitly permitted. Windows Defender Application Guard is a security feature of Windows 10 that helps protect against malicious websites and apps by running them in a isolated, virtualized environment. While it can help prevent malicious software from being executed on the workstations, it is not designed to control which specific applications can be run on the workstations. To meet the goal of ensuring that the workstations are only able to run applications that you have explicitly permitted, you will need to use additional controls such as AppLocker or an app deployment policy in Microsoft Intune. These tools allow you to specify a list of approved applications and block the execution of any other applications. In summary, the solution of using Windows Defender Application Guard alone does not meet the goal of ensuring that the workstations are only able to run applications that you have explicitly permitted.
upvoted 3 times
...
AK4U_111
2 years, 5 months ago
Be carfeul as they sound almost identical. windows defender application control vs windows defender application guard
upvoted 1 times
...
MR_Eliot
3 years ago
Selected Answer: B
B is correct.
upvoted 2 times
...
AL99
3 years, 1 month ago
Agree B "No"|
upvoted 2 times
...
Garito
3 years, 2 months ago
Selected Answer: B
Application Control and not Application Guard
upvoted 4 times
...
ameli8222
3 years, 3 months ago
Selected Answer: B
Its B. App control would be the right answer
upvoted 3 times
...
b3arb0yb1m
3 years, 4 months ago
B - Windows Defender Application Control.
upvoted 2 times
...
GLL
3 years, 4 months ago
It should be Application Control?
upvoted 3 times
...
Duyons
3 years, 5 months ago
Selected Answer: B
Correct Answer is B - Windows Defender Application Control is designed to protect PCs against malware and other untrusted software. It prevents malicious code from running by ensuring that only approved code, that you know, can be run. Windows Defender Application Control is a software-based security layer that enforces an explicit list of software that is allowed to run on a PC. On its own, Application Control does not have any hardware or firmware prerequisites. Application Control policies deployed with Configuration Manager enable a policy on PCs in targeted collections that meet the minimum Windows version and SKU requirements outlined in this article. Optionally, hypervisor-based protection of Application Control policies deployed through Configuration Manager can be enabled through Group Policy on capable hardware.
upvoted 3 times
...
handsofthelp
3 years, 5 months ago
Wrong. Should be Microsoft Defender Application Control.
upvoted 3 times
...
Nen0
3 years, 5 months ago
Right answer is 'No'. Solution requires Application Control, not Application Guard.
upvoted 4 times
...
ANDREVOX
3 years, 5 months ago
Answer is B. Application control is a security approach designed to protect against malicious code (also known as malware) executing on systems. While application control is primarily designed to prevent the execution and spread of malicious code, it can also prevent the installation or use of unapproved applications. Application Guard, a hardware-based endpoint defense, is a security tool that is built into Microsoft Edge. Application Guard isolates enterprise-defined untrusted sites from the desktop (host) in a virtual machine (VM) to prevent malicious activity from reaching the desktop. For Microsoft Office, Application Guard helps prevents untrusted Word, PowerPoint and Excel files from accessing trusted resources. ... This container isolation means that if the untrusted site or file turns out to be malicious, the host device is protected, and the attacker can't get to your enterprise data.
upvoted 3 times
...
DLSN
3 years, 7 months ago
https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control
upvoted 3 times
...
angelize
3 years, 10 months ago
the answe is NO. Application Guard only affects Edge (and Office if you have a plugin= the correct anser should be App protection
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago