Courseiva

SSCP Systems and Application Security Practice Question

An organization is hardening a new Windows server for production use. Which of the following is the most effective method to ensure that only approved applications can run?

⚠ Common exam trap

SSCP often tests the confusion between antivirus (denylist, detects known bad) and application allowlisting (only approved apps run), tempting candidates to pick Defender Antivirus as if it guaranteed only approved software executes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure AppLocker or Windows Defender Application Control

AppLocker and Windows Defender Application Control (WDAC) are the native Windows mechanisms that enforce application allowlisting by permitting only approved executables, scripts, and installers to run. They operate via policy at the kernel/OS level and are the correct control for restricting execution to approved software. This directly satisfies the requirement that only approved applications can run.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable BitLocker drive encryption

    Why it's wrong here

    BitLocker encrypts volumes at rest, protecting data if a disk is stolen; it places no restriction on which executables launch. Full-disk encryption is tempting because it is a standard server-hardening control, but it would be the right choice for confidentiality of data at rest, not application allowlisting.

  • ✗

    Enable User Account Control (UAC)

    Why it's wrong here

    UAC prompts for elevation when administrative actions occur; it does not restrict which executables may run. Application control via AppLocker or WDAC enforces an allowlist of approved binaries, which is the actual mechanism this scenario requires.

  • ✓

    Configure AppLocker or Windows Defender Application Control

    Why this is correct

    AppLocker and Windows Defender Application Control enforce application allowlisting, permitting only explicitly approved executables to run. This directly satisfies the requirement that only approved applications execute, unlike antivirus scanning or firewall rules, which detect or block traffic rather than restrict which programs may launch.

  • ✗

    Install Windows Defender Antivirus

    Why it's wrong here

    Antivirus detects known malware signatures but does not restrict execution to an approved list; AppLocker or Windows Defender Application Control enforces that. Signature-based scanning is tempting because it blocks malicious software, yet it permits any unsigned or unknown executable to run, so it cannot whitelist applications.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.