SSCP Systems and Application Security Practice Question
A security engineer is hardening a Windows workstation. Which TWO configurations reduce the attack surface by limiting execution of unauthorized code? (Select TWO.)
⚠ Common exam trap
SSCP often tests whether candidates can distinguish application control (AppLocker/WDAC) from network controls (firewall) and data protection (BitLocker) — a common mistake is selecting firewall or BitLocker as a way to limit code execution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure AppLocker rules
AppLocker (A) is correct because it uses allow/deny rules based on publisher, path, or file hash to control which executables, scripts, and installers users can run, directly restricting unauthorized code execution. Windows Defender Application Control (D) is also correct because WDAC enforces code integrity policies at the kernel level, allowing only trusted, signed binaries to execute and blocking unauthorized or tampered code. Windows Firewall with Advanced Security (B) filters network traffic by port, protocol, and profile but does not govern local code execution, so it does not meet the requirement. BitLocker (C) provides full-disk encryption for data-at-rest confidentiality and does not prevent execution of unauthorized programs. Disabling AutoPlay (E) reduces a minor vector for automatic execution from removable media but is not a general code-execution control like AppLocker or WDAC.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure AppLocker rules
Why this is correct
AppLocker enforces allow or deny rules based on publisher signature, file path or hash, so only approved executables, scripts and installers run. This directly limits execution of unauthorised code, satisfying the stem's attack-surface reduction constraint on the Windows workstation.
- ✗
Enable Windows Firewall with Advanced Security
Why it's wrong here
Windows Firewall filters network traffic by port and protocol; it does not restrict which executables may run, so unauthorised code still launches. It is tempting because firewall hardening is a standard baseline step, and it would be correct for controlling inbound connections, not application execution.
- ✗
Enable BitLocker full-disk encryption
Why it's wrong here
BitLocker encrypts data at rest, protecting confidentiality if the disk is stolen; it does not restrict which code executes, so unauthorised binaries still run. It is tempting because it hardens the workstation, but its role is data-at-rest protection, not execution control.
- ✓
Enable Windows Defender Application Control (WDAC)
Why this is correct
WDAC enforces code integrity policies at the kernel level, permitting only binaries signed by trusted publishers or explicitly allowlisted. This blocks unauthorised executables and drivers from running, directly satisfying the stem's requirement to reduce attack surface by limiting unauthorised code execution.
- ✗
Disable AutoPlay
Why it's wrong here
Disabling AutoPlay stops removable media from launching handlers automatically, but it does not block execution of already-installed binaries or scripts, so unauthorised code still runs. It is tempting because it counters USB-borne malware propagation, which is its actual purpose.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.