CAS-004 Security Operations Practice Question
A security operations team is deploying a new endpoint agent. They want to enforce a policy that only executables signed by trusted publishers and with a valid certificate chain are allowed to run, even if the user has local administrator rights. Which Windows feature should they configure to meet this requirement?
⚠ Common exam trap
A common mix-up: candidates confuse application control features like AppLocker with kernel-enforced code integrity like WDAC, assuming they provide the same level of certificate validation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Windows Defender Application Control (WDAC)
Windows Defender Application Control (WDAC) is the correct choice because it enforces code integrity at the kernel level, requiring all executables to have a valid certificate chain from a trusted publisher. It cannot be bypassed by local administrators, unlike AppLocker or SRP. UAC only manages elevation prompts and does not validate signatures, so it fails to meet the strict policy requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Windows Defender Application Control (WDAC)
Why this is correct
WDAC is a kernel-enforced code integrity feature that can enforce policies requiring all executables to be signed by trusted publishers with a valid certificate chain. It operates at the kernel level and cannot be bypassed by local administrators, making it suitable for this strict requirement. It also supports audit mode and multiple policy formats.
- ✗
User Account Control (UAC)
Why it's wrong here
UAC prompts for elevation but does not enforce code signing or certificate chain validation. It is a consent mechanism, not an application control policy. Even with UAC set to always notify, a local administrator can run unsigned executables, so it does not meet the requirement of only allowing trusted signed binaries.
- ✗
Software Restriction Policies (SRP)
Why it's wrong here
SRP is a legacy feature that can block executables based on path, hash, or certificate rules, but it is not as robust as WDAC and does not enforce certificate chain validation for all binaries. It also has known bypasses and is not recommended for high-security environments where local admin rights must be constrained.
- ✗
AppLocker
Why it's wrong here
AppLocker can restrict which applications run based on publisher, path, or file hash, but it does not enforce certificate chain validity or block all unsigned executables by default. It is designed for application control, not as a strict code integrity mechanism that validates the entire certificate chain for every binary at load time.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.