Courseiva
Security Operations →mediumMultiple Choice

CAS-004 Security Operations Practice Question

A security operations team is deploying a new endpoint agent. They want to enforce a policy that only executables signed by trusted publishers and with a valid certificate chain are allowed to run, even if the user has local administrator rights. Which Windows feature should they configure to meet this requirement?

⚠ Common exam trap

A common mix-up: candidates confuse application control features like AppLocker with kernel-enforced code integrity like WDAC, assuming they provide the same level of certificate validation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Windows Defender Application Control (WDAC)

Windows Defender Application Control (WDAC) is the correct choice because it enforces code integrity at the kernel level, requiring all executables to have a valid certificate chain from a trusted publisher. It cannot be bypassed by local administrators, unlike AppLocker or SRP. UAC only manages elevation prompts and does not validate signatures, so it fails to meet the strict policy requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Windows Defender Application Control (WDAC)

    Why this is correct

    WDAC is a kernel-enforced code integrity feature that can enforce policies requiring all executables to be signed by trusted publishers with a valid certificate chain. It operates at the kernel level and cannot be bypassed by local administrators, making it suitable for this strict requirement. It also supports audit mode and multiple policy formats.

  • ✗

    User Account Control (UAC)

    Why it's wrong here

    UAC prompts for elevation but does not enforce code signing or certificate chain validation. It is a consent mechanism, not an application control policy. Even with UAC set to always notify, a local administrator can run unsigned executables, so it does not meet the requirement of only allowing trusted signed binaries.

  • ✗

    Software Restriction Policies (SRP)

    Why it's wrong here

    SRP is a legacy feature that can block executables based on path, hash, or certificate rules, but it is not as robust as WDAC and does not enforce certificate chain validation for all binaries. It also has known bypasses and is not recommended for high-security environments where local admin rights must be constrained.

  • ✗

    AppLocker

    Why it's wrong here

    AppLocker can restrict which applications run based on publisher, path, or file hash, but it does not enforce certificate chain validity or block all unsigned executables by default. It is designed for application control, not as a strict code integrity mechanism that validates the entire certificate chain for every binary at load time.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.