Courseiva

SSCP Systems and Application Security Practice Question

An organization is implementing Windows Defender Application Control (WDAC) to prevent unauthorized applications from running on company workstations. Which of the following best describes the primary security benefit of this approach?

⚠ Common exam trap

SSCP often tests the distinction between application allowlisting (WDAC) and adjacent controls like encryption, patching, or code signing, baiting candidates who conflate prevention of execution with integrity or confidentiality controls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It prevents execution of any application not explicitly allowed

WDAC is an application control mechanism that enforces an allowlist of approved code, blocking execution of any binary, script, or package not explicitly permitted by policy. This default-deny posture is its primary security benefit, preventing unauthorized or malicious executables from running even if they land on the endpoint.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    It prevents execution of any application not explicitly allowed

    Why this is correct

    WDAC enforces an allowlist model: only applications matching explicitly permitted publisher, hash or path rules may execute, blocking all else by default. This directly satisfies the requirement to prevent unauthorised applications from running, unlike audit-only or reputation-based approaches.

  • ✗

    It encrypts application binaries at rest

    Why it's wrong here

    WDAC governs code integrity by permitting only signed, allowlisted binaries to execute; it leaves binaries unencrypted on disk. Encryption at rest is the role of BitLocker or similar volume encryption, which would be correct if the requirement were protecting data on a lost or stolen workstation.

  • ✗

    It automatically updates applications from a trusted source

    Why it's wrong here

    WDAC enforces an allowlist controlling which binaries may execute; it does not fetch or patch software. Automatic updates belong to patch-management tooling such as Windows Update or Configuration Manager, which would be the right answer if the scenario asked how to keep approved applications current rather than how to block unapproved ones.

  • ✗

    It ensures that all applications are digitally signed

    Why it's wrong here

    WDAC enforces an allowlist: only applications matching trusted publisher, hash or path rules may execute, so unsigned but explicitly permitted binaries still run. Requiring every application to be digitally signed is a stricter policy than WDAC itself imposes. Signing enforcement suits environments mandating publisher verification across all software.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on SSCP

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A security analyst is hardening a new Windows server. Which configuration would MOST effectively reduce the attack surface by limiting the software that can execute?

easy
  • A.Enable Windows Defender Antivirus
  • B.Disable AutoPlay
  • C.Enable User Account Control (UAC)
  • ✓ D.Configure AppLocker rules

Why D: AppLocker is a Windows application control feature that lets administrators define allow/deny rules based on publisher, path, or file hash, thereby restricting which executables, scripts, and installers can run. This directly limits the software that can execute, which is the most effective way to reduce attack surface against unauthorized or malicious code. Antivirus, AutoPlay, and UAC address other threats but do not control what software is permitted to run.

Variation 2. A company is implementing application whitelisting on all endpoints. Which of the following is a primary consideration for maintaining operational efficiency?

easy
  • A.Ensuring that all users have local administrator rights
  • B.Deploying a host-based firewall on each endpoint
  • ✓ C.Establishing a process to add approved applications to the whitelist
  • D.Disabling Windows Defender Antivirus to reduce resource usage

Why C: Application whitelisting only allows approved applications to run. To maintain operational efficiency, organizations must have a streamlined process to review and add new or updated applications to the whitelist as business needs evolve. Without this, users may be blocked from necessary tools, causing productivity loss.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.