GSEC Endpoint Security Practice Question
A security team wants to implement application whitelisting on a set of Windows 10 workstations to prevent users from running unauthorized executables. They need a solution that integrates with Group Policy and allows rules based on file path, hash, or publisher. Which built-in Windows feature should they use?
⚠ Common exam trap
It's easy for candidates to confuse AppLocker with WDAC or SRP; while all can restrict applications, AppLocker is the one that best fits the described requirements and is not deprecated.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AppLocker
AppLocker is the built-in Windows feature designed for application whitelisting, with rule types based on path, hash, or publisher, and it integrates with Group Policy. WDAC is more complex and less Group Policy-centric, SRP is deprecated, and Windows Defender Firewall does not control application execution. Therefore, AppLocker is the correct solution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Software Restriction Policies (SRP)
Why it's wrong here
SRP is an older feature that also provides application whitelisting, but it is deprecated in favor of AppLocker and lacks some of the flexibility and rule types (e.g., publisher rules) that AppLocker offers. It integrates with Group Policy but is not the recommended solution for Windows 10. Therefore, it is not the correct choice.
- ✗
Windows Defender Application Control (WDAC)
Why it's wrong here
WDAC (formerly Device Guard) is also a Windows feature for application control, but it is primarily designed for stronger, kernel-level enforcement and is often used in high-security environments. While it can be used for whitelisting, it does not integrate as seamlessly with Group Policy and is more complex to manage. The scenario specifies Group Policy integration and rule types that align with AppLocker. Thus, WDAC is not the best fit here.
- ✓
AppLocker
Why this is correct
AppLocker is a built-in Windows feature that allows administrators to create rules based on file path, hash, or publisher to control which applications and scripts users can run. It integrates with Group Policy for centralized management. This directly meets the requirement for application whitelisting on Windows 10 workstations. Therefore, AppLocker is the correct choice.
- ✗
Windows Defender Firewall
Why it's wrong here
Windows Defender Firewall controls network traffic, not application execution. It cannot prevent users from running unauthorized executables. While it is a security feature, it does not provide application whitelisting. Hence, it is not the correct answer for this requirement.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.