nerdexam
Microsoft

MD-102 · Question #37

You have 200 computers that run Windows 10. The computers are joined to Microsoft Azure Active Directory (Azure AD) and enrolled in Microsoft Intune. You need to ensure that only applications that…

The correct answer is D. Microsoft Defender Application Control. Application control can help mitigate these types of security threats by restricting the applications that users are allowed to run and the code that runs in the System Core (kernel). Application control policies can also block unsigned scripts and MSIs, and restrict Windows…

Submitted by luis.pe· Apr 18, 2026Protect devices

Question

You have 200 computers that run Windows 10. The computers are joined to Microsoft Azure Active Directory (Azure AD) and enrolled in Microsoft Intune. You need to ensure that only applications that you explicitly allow can run on the computers. What should you use?

Options

  • AWindows Defender Credential Guard
  • BWindows Defender Exploit Guard
  • CWindows Defender Application Guard
  • DMicrosoft Defender Application Control

How the community answered

(20 responses)
  • A
    15% (3)
  • B
    5% (1)
  • C
    10% (2)
  • D
    70% (14)

Explanation

Application control can help mitigate these types of security threats by restricting the applications that users are allowed to run and the code that runs in the System Core (kernel). Application control policies can also block unsigned scripts and MSIs, and restrict Windows PowerShell to run in Constrained Language Mode. https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender- application-control/windows-defender-application-control

Topics

#Microsoft Defender Application Control#Application Allowlisting#Windows 10#Intune

Community Discussion

No community discussion yet for this question.

Full MD-102 Practice