nerdexam
GIAC

GSEC · Question #49

Which of the following features of Windows 7 allows an administrator to both passively review installed software and configure policies to prevent out-of-date or insecure software from running?

The correct answer is C. App Locker. AppLocker in Windows 7 provides both auditing capabilities to review installed/running software and rule-based policies to block unauthorized or insecure applications from executing.

Windows and Malware

Question

Which of the following features of Windows 7 allows an administrator to both passively review installed software and configure policies to prevent out-of-date or insecure software from running?

Options

  • ADirect Access
  • BSoftware Restriction Policies
  • CApp Locker
  • DUser Account Control

How the community answered

(33 responses)
  • A
    15% (5)
  • B
    3% (1)
  • C
    76% (25)
  • D
    6% (2)

Why each option

AppLocker in Windows 7 provides both auditing capabilities to review installed/running software and rule-based policies to block unauthorized or insecure applications from executing.

ADirect Access

Direct Access is a remote connectivity feature that allows domain-joined clients to connect to internal resources without a VPN, and has no application control or software review functionality.

BSoftware Restriction Policies

Software Restriction Policies is an older mechanism that can block software by path or hash, but lacks AppLocker's auditing and publisher-based rules, and does not support the passive review mode described.

CApp LockerCorrect

AppLocker allows administrators to create allow/deny rules based on publisher, path, or file hash, enabling both passive auditing mode (to inventory what runs) and enforced policy mode (to block out-of-date or insecure software). It supersedes Software Restriction Policies and integrates with Group Policy for enterprise-wide enforcement. Its audit-only mode is specifically designed for the passive review use case described in the question.

DUser Account Control

User Account Control prompts for elevation of privilege when administrative actions are attempted, but it does not inventory installed software or enforce policies against specific applications running.

Concept tested: AppLocker application control and auditing policies

Source: https://learn.microsoft.com/en-us/windows/security/application-security/application-control/windows-defender-application-control/applocker/applocker-overview

Topics

#AppLocker#software restriction#application control#Windows 7

Community Discussion

No community discussion yet for this question.

Full GSEC Practice