nerdexam
CompTIA

CAS-003 · Question #588

A company uses an enterprise desktop imaging solution to manage deployment of its desktop computers. Desktop computer users are only permitted to use software that is part of the baseline image…

The correct answer is C. Application whitelisting. Application whitelisting is the technical control that enforces a policy where only pre-approved, baseline-image software is permitted to run on corporate desktops.

Enterprise Security Operations

Question

A company uses an enterprise desktop imaging solution to manage deployment of its desktop computers. Desktop computer users are only permitted to use software that is part of the baseline image. Which of the following technical solutions was MOST likely deployed by the company to ensure only known-good software can be installed on corporate desktops?

Options

  • ANetwork access control
  • BConfiguration Manager
  • CApplication whitelisting
  • DFile integrity checks

How the community answered

(49 responses)
  • A
    4% (2)
  • B
    2% (1)
  • C
    88% (43)
  • D
    6% (3)

Why each option

Application whitelisting is the technical control that enforces a policy where only pre-approved, baseline-image software is permitted to run on corporate desktops.

ANetwork access control

Network access control enforces device compliance before granting network access but does not restrict which applications can execute on the endpoint once it is connected.

BConfiguration Manager

Configuration Manager is a software deployment and patch management platform that can push software but does not inherently block unauthorized applications from being installed or run.

CApplication whitelistingCorrect

Application whitelisting maintains an explicit list of approved executables and blocks any application not on that list from running, regardless of how it arrived on the system. This directly enforces the business rule that users may only use software included in the standard desktop image. It is a default-deny execution control that stops unauthorized, unvetted, or malicious software from launching even if it is successfully installed.

DFile integrity checks

File integrity checks detect unauthorized modifications to existing files after the fact but do not prevent new, unauthorized software from being installed or executed.

Concept tested: Application whitelisting to enforce software baseline policy

Source: https://csrc.nist.gov/publications/detail/sp/800-167/final

Topics

#application whitelisting#endpoint hardening#software control#desktop security

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice