nerdexam
Palo_Alto_Networks

PCCET · Question #224

What is a method a security operating platform uses to reduce threats?

The correct answer is A. Enabling applications based on user and device requirements and blocking unneeded. This question asks for a method a security operating platform uses to reduce threats.

Submitted by yuki_2020· Apr 18, 2026Cybersecurity Foundations

Question

What is a method a security operating platform uses to reduce threats?

Options

  • AEnabling applications based on user and device requirements and blocking unneeded
  • BAllowing all SaaS applications
  • CEnabling all cloud native applications that are part of the Dev/Sec/Ops CI/CD pipeline
  • DDisabling all SaaS applications

How the community answered

(25 responses)
  • A
    88% (22)
  • B
    8% (2)
  • D
    4% (1)

Why each option

This question asks for a method a security operating platform uses to reduce threats.

AEnabling applications based on user and device requirements and blocking unneededCorrect

A security operating platform effectively reduces threats by implementing strict application control, enabling only applications based on legitimate user and device requirements while actively blocking unneeded or unauthorized software. This 'least privilege' approach minimizes the attack surface by preventing the execution of potentially malicious or vulnerable programs.

BAllowing all SaaS applications

Allowing all SaaS applications without proper vetting and control introduces significant security risks, as it can expose the organization to unmanaged or vulnerable third-party services.

CEnabling all cloud native applications that are part of the Dev/Sec/Ops CI/CD pipeline

Enabling all cloud-native applications, even within a CI/CD pipeline, without robust security validation and policy enforcement, is not a method to reduce threats and can introduce vulnerabilities.

DDisabling all SaaS applications

Disabling all SaaS applications is an extreme measure that would severely disrupt business operations and productivity, making it an impractical and ineffective security strategy.

Concept tested: Security operating platform threat reduction strategy

Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/attack-surface-reduction-rules-reference

Topics

#Application control#Threat reduction#Security policies#Least privilege

Community Discussion

No community discussion yet for this question.

Full PCCET Practice