SSCP Systems and Application Security Practice Question
A security analyst is hardening a new Windows server. Which configuration would MOST effectively reduce the attack surface by limiting the software that can execute?
⚠ Common exam trap
The trap is confusing detection-based controls (antivirus) or privilege controls (UAC) with execution control—only AppLocker (or similar WDAC) actually restricts what software is allowed to run.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure AppLocker rules
AppLocker is a Windows application control feature that lets administrators define allow/deny rules based on publisher, path, or file hash, thereby restricting which executables, scripts, and installers can run. This directly limits the software that can execute, which is the most effective way to reduce attack surface against unauthorized or malicious code. Antivirus, AutoPlay, and UAC address other threats but do not control what software is permitted to run.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Windows Defender Antivirus
Why it's wrong here
Windows Defender Antivirus detects and blocks known malicious files after they attempt to run, rather than defining which software is permitted to execute. Application control allowlisting restricts execution to approved binaries. Defender is the right control for malware detection, not execution restriction.
- ✗
Disable AutoPlay
Why it's wrong here
Disabling AutoPlay stops automatic execution of removable media content, a narrow vector, but does not govern which programs may run on the server. Application control allowlisting enforces that. AutoPlay hardening suits endpoint media-handling risks, not broad software execution limitation.
- ✗
Enable User Account Control (UAC)
Why it's wrong here
User Account Control gates privilege elevation for administrative actions; it does not restrict which applications may execute. Application control or AppLocker policies define allowed executables. UAC would be relevant when limiting unauthorised privilege escalation, not software execution.
- ✓
Configure AppLocker rules
Why this is correct
AppLocker enforces allow/deny rules on which executables, scripts and installers may run, directly restricting software execution on the Windows server and shrinking the attack surface. Unlike firewall or patch controls, it addresses the constraint of limiting what can execute.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.