70-685 · Question #189
All client computers on your company network run Windows 7 and are members of an Active Directory Domain Services domain. AppLocker is configured to allow only approved applications to run…
The correct answer is A. Create Executable Rules by selecting the Create Default Rules option. Many organizations are. implementing standard user policies, which allow users to log on to their computers only as a standard user. With Windows Vista®, this task became easier. However, more independent software vendors (ISVs) are creating per-user applications that do not require administrative…
Question
All client computers on your company network run Windows 7 and are members of an Active Directory Domain Services domain. AppLocker is configured to allow only approved applications to run. Employees with standard user account permissions are able to run applications that install into the user profile folder. You need to prevent standard users from running unauthorized applications. What should you do?
Options
- ACreate Executable Rules by selecting the Create Default Rules option. Many organizations are
- BCreate Windows Installer Rules by selecting the Create Default Rules option.
- CCreate the following Windows Installer Rule:
- DCreate the following Executable Rule:
How the community answered
(32 responses)- A84% (27)
- B9% (3)
- C3% (1)
- D3% (1)
Explanation
implementing standard user policies, which allow users to log on to their computers only as a standard user. With Windows Vista®, this task became easier. However, more independent software vendors (ISVs) are creating per-user applications that do not require administrative rights to be installed and that are installed and run in the user profile folder. As a result, standard users can install many applications and circumvent the application lockdown policy. With AppLocker, you can prevent users from installing and running per-user applications. To prevent standard users from running per-user: To open the Local Security Policy MMC snap-in, click Start, type secpol.msc in the Search programs and files box, and then press ENTER. In the console tree, double-click Application Control Policies, and then double-click AppLocker. Right-click Executable Rules, and then click Create Default Rules.
Topics
Community Discussion
No community discussion yet for this question.