nerdexam
Microsoft

AZ-801 · Question #135

NOTE: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might…

The correct answer is B. No. Reputation-based protection (SmartScreen) does not restrict which applications can modify protected folders; Controlled Folder Access is the correct Windows Security feature for that requirement.

Secure Windows Server on-premises and hybrid infrastructures

Question

NOTE: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a generation 1 Azure virtual machine named VM1 that runs Windows Server and is joined to an Active Directory domain. You need to ensure that only specific applications can modify the data in protected folders on Server1. Solution: From App & browser control, you configure Reputation-based protection. Does this meet the goal?

Options

  • AYes
  • BNo

How the community answered

(43 responses)
  • A
    23% (10)
  • B
    77% (33)

Why each option

Reputation-based protection (SmartScreen) does not restrict which applications can modify protected folders; Controlled Folder Access is the correct Windows Security feature for that requirement.

AYes

Reputation-based protection (SmartScreen) evaluates the trustworthiness of downloaded files and unknown apps but does not provide the ability to whitelist or restrict which applications can write to specific protected folders.

BNoCorrect

To allow only specific applications to modify data in protected folders, Controlled Folder Access must be enabled under Virus and threat protection settings in Windows Security - not Reputation-based protection. Reputation-based protection configures SmartScreen to evaluate downloads and untrusted apps based on cloud reputation data, which is an entirely separate security capability that does not manage folder-level write permissions for applications.

Concept tested: Controlled Folder Access vs Reputation-based protection in Windows Security

Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/controlled-folders

Topics

#Windows Security#Microsoft Defender#Endpoint Protection#Application Control

Community Discussion

No community discussion yet for this question.

Full AZ-801 Practice