Courseiva

SSCP Systems and Application Security Practice Question

An organization is hardening its Windows servers. Which built-in Windows feature can be used to enforce application whitelisting, ensuring only approved executables run?

⚠ Common exam trap

Candidates often confuse access control features like UAC or antivirus with application whitelisting; candidates may think UAC restricts applications, but it only controls elevation, not execution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AppLocker

AppLocker is a Windows built-in feature introduced in Windows 7 and Server 2008 R2 that allows administrators to create and enforce rules specifying which applications and files users can run. It uses a whitelisting model based on file attributes such as publisher, path, or hash, and can be configured via Group Policy or PowerShell cmdlets. By default, AppLocker blocks any executable not explicitly allowed, thus ensuring only approved executables run. This directly meets the requirement for application whitelisting on Windows servers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    BitLocker

    Why it's wrong here

    BitLocker encrypts volumes at rest to prevent offline data theft; it places no restriction on which executables may launch once Windows is running. It is tempting because it is a built-in hardening control, but full-disk encryption addresses confidentiality of stored data, not application execution control.

  • ✗

    Windows Defender Antivirus

    Why it's wrong here

    Windows Defender Antivirus blocks files matching known malicious signatures or behaviour; it permits any unrecognised executable to run, so it cannot enforce an approved-only list. It is tempting because it is built-in endpoint protection, but signature detection is a denylist model, the opposite of whitelisting.

  • ✓

    AppLocker

    Why this is correct

    AppLocker applies policy-based allow lists that restrict which executables, scripts and installers may run, using publisher, path or hash rules. This enforces application whitelisting natively on Windows servers, satisfying the hardening requirement without third-party agents.

  • ✗

    User Account Control (UAC)

    Why it's wrong here

    UAC prompts for elevation when an action requires administrative rights; it does not maintain an allowlist of permitted executables, so unapproved binaries still launch under a standard token. It is tempting because it gates privileged actions, but that is consent for elevation, not application control.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.