CAS-003 · Question #890
An organization recently experienced losses caused by users who installed applications from unauthorized sources on their smartphones. The organization wants to reduce the risk of reoccurrence but…
The correct answer is A. Configure and deploy an AD Group Policy that enforces an application whitelist on all x86-64. Enforcing application whitelists via Group Policy prevents unauthorized application installation on managed endpoints while enterprise-level policy enforcement provides the required visibility and reporting.
Question
An organization recently experienced losses caused by users who installed applications from unauthorized sources on their smartphones. The organization wants to reduce the risk of reoccurrence but increase the monitoring and reporting of mobile device security at the enterprise level. Which of the following approaches would BEST meet these objectives?
Options
- AConfigure and deploy an AD Group Policy that enforces an application whitelist on all x86-64
- BModify the organization's MAM configuration to capture events associated with application
- CSet GPOs to enable the enterprise SIEM tool to collect all application and server logs, and
- DEnforce device configurations with agents that leverage the devices' APIs, and feed logs and
How the community answered
(26 responses)- A77% (20)
- B12% (3)
- C4% (1)
- D8% (2)
Why each option
Enforcing application whitelists via Group Policy prevents unauthorized application installation on managed endpoints while enterprise-level policy enforcement provides the required visibility and reporting.
Configuring and deploying Group Policy to enforce an application whitelist directly prevents users from installing applications from unauthorized sources, addressing the root cause of the losses. Combining this with consistent enterprise-level policy enforcement ensures the control applies uniformly across all managed devices in scope. This approach simultaneously meets the risk-reduction objective by blocking unauthorized installs and the monitoring objective through centralized policy compliance reporting.
Modifying the MAM configuration to capture application-related events improves detection and monitoring but is a detective control that does not prevent users from installing unauthorized applications in the first place.
Setting GPOs to collect logs and feed them to the enterprise SIEM improves visibility but remains a detective control - it does not enforce application restrictions or prevent unauthorized installations from occurring.
Enforcing device configurations with API-leveraging agents and feeding logs to a central system addresses monitoring but does not implement the application whitelist enforcement needed to prevent unauthorized installs.
Concept tested: Application whitelisting and Group Policy enforcement for endpoint control
Source: https://learn.microsoft.com/en-us/windows/security/application-security/application-control/app-control-for-business/applocker/applocker-overview
Topics
Community Discussion
No community discussion yet for this question.