SSCP Systems and Application Security Practice Question
An organization is implementing Windows Defender Application Control (WDAC) to prevent unauthorized applications from running on company workstations. Which of the following best describes the primary security benefit of this approach?
⚠ Common exam trap
SSCP often tests the distinction between application allowlisting (WDAC) and adjacent controls like encryption, patching, or code signing, baiting candidates who conflate prevention of execution with integrity or confidentiality controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It prevents execution of any application not explicitly allowed
WDAC is an application control mechanism that enforces an allowlist of approved code, blocking execution of any binary, script, or package not explicitly permitted by policy. This default-deny posture is its primary security benefit, preventing unauthorized or malicious executables from running even if they land on the endpoint.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
It prevents execution of any application not explicitly allowed
Why this is correct
WDAC enforces an allowlist model: only applications matching explicitly permitted publisher, hash or path rules may execute, blocking all else by default. This directly satisfies the requirement to prevent unauthorised applications from running, unlike audit-only or reputation-based approaches.
- ✗
It encrypts application binaries at rest
Why it's wrong here
WDAC governs code integrity by permitting only signed, allowlisted binaries to execute; it leaves binaries unencrypted on disk. Encryption at rest is the role of BitLocker or similar volume encryption, which would be correct if the requirement were protecting data on a lost or stolen workstation.
- ✗
It automatically updates applications from a trusted source
Why it's wrong here
WDAC enforces an allowlist controlling which binaries may execute; it does not fetch or patch software. Automatic updates belong to patch-management tooling such as Windows Update or Configuration Manager, which would be the right answer if the scenario asked how to keep approved applications current rather than how to block unapproved ones.
- ✗
It ensures that all applications are digitally signed
Why it's wrong here
WDAC enforces an allowlist: only applications matching trusted publisher, hash or path rules may execute, so unsigned but explicitly permitted binaries still run. Requiring every application to be digitally signed is a stricter policy than WDAC itself imposes. Signing enforcement suits environments mandating publisher verification across all software.
Visual reference
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on SSCP
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A security analyst is hardening a new Windows server. Which configuration would MOST effectively reduce the attack surface by limiting the software that can execute?
easy- A.Enable Windows Defender Antivirus
- B.Disable AutoPlay
- C.Enable User Account Control (UAC)
- ✓ D.Configure AppLocker rules
Why D: AppLocker is a Windows application control feature that lets administrators define allow/deny rules based on publisher, path, or file hash, thereby restricting which executables, scripts, and installers can run. This directly limits the software that can execute, which is the most effective way to reduce attack surface against unauthorized or malicious code. Antivirus, AutoPlay, and UAC address other threats but do not control what software is permitted to run.
Variation 2. A company is implementing application whitelisting on all endpoints. Which of the following is a primary consideration for maintaining operational efficiency?
easy- A.Ensuring that all users have local administrator rights
- B.Deploying a host-based firewall on each endpoint
- ✓ C.Establishing a process to add approved applications to the whitelist
- D.Disabling Windows Defender Antivirus to reduce resource usage
Why C: Application whitelisting only allows approved applications to run. To maintain operational efficiency, organizations must have a streamlined process to review and add new or updated applications to the whitelist as business needs evolve. Without this, users may be blocked from necessary tools, causing productivity loss.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.