SC-100 · Question #160
You have a Microsoft 365 subscription and an Azure subscription. Microsoft 365 Defender and Microsoft Defender for Cloud are enabled. The Azure subscription contains 50 virtual machines. Each…
The correct answer is D. application control policies in Microsoft Defender for Endpoint. Application control policies in Microsoft Defender for Endpoint leverage Windows Defender Application Control (WDAC) to enforce which applications are permitted to run on Windows Server machines. WDAC operates at the kernel level and can block unauthorized executables and…
Question
You have a Microsoft 365 subscription and an Azure subscription. Microsoft 365 Defender and Microsoft Defender for Cloud are enabled. The Azure subscription contains 50 virtual machines. Each virtual machine runs different applications on Windows Server 2019. You need to recommend a solution to ensure that only authorized applications can run on the virtual machines. If an unauthorized application attempts to run or be installed, the application must be blocked automatically until an administrator authorizes the application. Which security control should you recommend?
Options
- AAzure AD Conditional Access App Control policies
- BAzure Security Benchmark compliance controls in Defender for Cloud
- Capp protection policies in Microsoft Endpoint Manager
- Dapplication control policies in Microsoft Defender for Endpoint
How the community answered
(38 responses)- A18% (7)
- B8% (3)
- C3% (1)
- D71% (27)
Explanation
Application control policies in Microsoft Defender for Endpoint leverage Windows Defender Application Control (WDAC) to enforce which applications are permitted to run on Windows Server machines. WDAC operates at the kernel level and can block unauthorized executables and scripts automatically until an administrator adds them to an approved policy. Defender for Endpoint is already integrated across the 50 VMs in this scenario. Azure AD Conditional Access App Control (A) governs cloud app session controls, not OS-level process execution. Azure Security Benchmark compliance controls (B) surface configuration recommendations but do not actively block applications. App protection policies in Endpoint Manager (C) target mobile application data protection, not server-side application execution control.
Topics
Community Discussion
No community discussion yet for this question.