SC-100 · Question #137
You have a Microsoft 365 subscription and an Azure subscription. Microsoft 365 Defender and Microsoft Defender for Cloud are enabled. The Azure subscription contains 50 virtual machines. Each…
The correct answer is C. application control policies in Microsoft Defender for Endpoint. Application control policies in Microsoft Defender for Endpoint (C) leverage Windows Defender Application Control (WDAC) and AppLocker, which enforce allowlists of authorized applications directly on Windows Server endpoints. Unauthorized applications are blocked at the OS…
Question
You have a Microsoft 365 subscription and an Azure subscription. Microsoft 365 Defender and Microsoft Defender for Cloud are enabled. The Azure subscription contains 50 virtual machines. Each virtual machine runs different applications on Windows Server 2019. You need to recommend a solution to ensure that only authorized applications can run on the virtual machines. If an unauthorized application attempts to run or be installed, the application must be blocked automatically until an administrator authorizes the application. Which security control should you recommend?
Options
- AOAuth app policies in Microsoft Defender for Cloud Apps
- BAzure Security Benchmark compliance controls in Defender for Cloud
- Capplication control policies in Microsoft Defender for Endpoint
- Dapp discovery anomaly detection policies in Microsoft Defender for Cloud Apps
How the community answered
(36 responses)- A14% (5)
- B6% (2)
- C72% (26)
- D8% (3)
Explanation
Application control policies in Microsoft Defender for Endpoint (C) leverage Windows Defender Application Control (WDAC) and AppLocker, which enforce allowlists of authorized applications directly on Windows Server endpoints. Unauthorized applications are blocked at the OS level and remain blocked until an administrator explicitly authorizes them - exactly matching the requirement. OAuth app policies (A) and app discovery anomaly detection (D) in Defender for Cloud Apps operate on SaaS/cloud application access, not on-VM process execution control. Azure Security Benchmark compliance controls (B) assess configuration posture and generate recommendations but do not enforce application execution blocking. MDE is the correct tool for host-level application control on Windows Server 2019 VMs.
Topics
Community Discussion
No community discussion yet for this question.