210-250 · Question #117
You have deployed an enterprise-wide host/endpoint technology for all of the company corporate PCs. Management asks you to block a selected set of applications on all corporate PCs. Which technology…
The correct answer is B. application whitelisting/blacklisting. Application whitelisting and blacklisting is the endpoint technology specifically designed to allow or deny execution of selected applications on corporate PCs.
Question
You have deployed an enterprise-wide host/endpoint technology for all of the company corporate PCs. Management asks you to block a selected set of applications on all corporate PCs. Which technology is the best option?
Options
- Aantivirus/antispyware software
- Bapplication whitelisting/blacklisting
- Chost-based IDS
- Dnetwork NGFW
How the community answered
(20 responses)- A5% (1)
- B70% (14)
- C10% (2)
- D15% (3)
Why each option
Application whitelisting and blacklisting is the endpoint technology specifically designed to allow or deny execution of selected applications on corporate PCs.
Antivirus and antispyware software detects and removes malware based on signatures or behavior, but is not designed to block specific legitimate or policy-restricted applications by administrative choice.
Application whitelisting and blacklisting allows administrators to define explicit lists of approved or denied applications, preventing unauthorized or policy-restricted software from executing on managed endpoints. This technology provides direct, granular control over which programs can run, making it the most precise solution for the described requirement. It operates at the host level, ensuring policy enforcement regardless of network connectivity.
A host-based IDS monitors and alerts on suspicious activity but does not enforce application execution blocking based on administrative policy.
A network next-generation firewall operates at the network perimeter and cannot directly enforce which applications are permitted to execute on individual endpoint operating systems.
Concept tested: Endpoint application whitelisting and blacklisting control
Source: https://csrc.nist.gov/publications/detail/sp/800-167/final
Topics
Community Discussion
No community discussion yet for this question.