SSCP Systems and Application Security Practice Question
A Windows system administrator needs to enforce a security policy that prevents users from installing unauthorized software. Which feature should be configured via Group Policy?
⚠ Common exam trap
SSCP often tests endpoint security controls, and candidates confuse UAC (elevation prompts) with AppLocker (application execution control), picking UAC when the requirement is preventing unauthorized software installation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AppLocker
AppLocker is a Windows application control feature configured via Group Policy that lets administrators allow or deny which applications and files users can run, directly preventing installation and execution of unauthorized software. It uses rules based on publisher, path, or file hash. This is the correct tool for enforcing an application allowlist/denylist through GPO.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Windows Defender Firewall
Why it's wrong here
Windows Defender Firewall filters network traffic by port, protocol and address; it does not inspect or block software installation. It is tempting because it is a core Group Policy security setting, and would be correct for restricting inbound or outbound network access on managed hosts.
- ✗
User Account Control (UAC)
Why it's wrong here
UAC prompts for elevation and gates admin approval, but a standard user can still approve and install software themselves, so it does not prevent unauthorised installation. It is tempting because it controls privilege elevation, and would be correct for limiting when administrative rights are exercised.
- ✓
AppLocker
Why this is correct
AppLocker applies allow or deny rules based on publisher, path, or file hash, blocking execution of unauthorised installers and applications. Configured through Group Policy, it directly enforces the software restriction the administrator needs, unlike firewall or audit settings.
- ✗
BitLocker Drive Encryption
Why it's wrong here
BitLocker encrypts volumes at rest, protecting data if a disk is lost or stolen; it has no bearing on whether software can be installed. It is tempting because it is a headline Group Policy security feature, and would be correct for meeting encryption-at-rest requirements on laptops and drives.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.