Certificate
The Certificate condition is not a separate AppLocker condition; it is part of the Publisher condition. However, in AppLocker, the Publisher condition uses certificate details to create rules. Since the question asks for TWO conditions, and the Publisher condition encompasses certificate-based rules, selecting Publisher is correct. The other correct condition is not listed; but note that AppLocker also allows file hash. However, to allow only signed apps, Publisher is essential. The second correct condition is not explicitly listed, but the question expects two; however, the only correct one is Publisher. This indicates a flaw in the question design. To adhere to the rules, I must ensure exactly two correct answers. Let me revise the options to include 'File hash' as correct? No, that's not for signed apps. Actually, AppLocker has three rule conditions: Publisher, Path, and File hash. To allow only signed apps, Publisher is necessary. But you might also use File hash to allow specific unsigned apps if needed, but the requirement is to allow only signed apps. So only Publisher is correct. This is a problem. I need to adjust the question to have two correct answers. Perhaps the second correct answer is 'File hash' if the administrator wants to allow specific signed apps by hash? But that's not efficient. Alternatively, the question could be about Windows Defender Application Control (WDAC), but AppLocker is specified. Let me rethink: In AppLocker, to allow only signed applications, you can use Publisher rules. You might also use a default rule that allows all signed apps? Actually, AppLocker default rules allow all users to run all apps in Program Files and Windows folders, but that's not based on signature. To enforce signed-only, you create a Publisher rule that allows all signed apps from trusted publishers, and then set the default action to deny. So only Publisher condition is needed. But the question asks for TWO. I need to change the scenario to ask for two conditions that are used together. Perhaps the administrator wants to allow signed apps and also block specific unsigned apps by hash? That would be two conditions. But the stem says 'allow only signed applications from trusted publishers to run, while blocking all other executables.' That implies a whitelist approach. In AppLocker, you can create a Publisher rule to allow signed apps, and then create a File hash rule to allow a specific unsigned app if needed, but that would violate 'only signed'. So I must revise the question to have two correct answers. Let me change the stem to: 'Which TWO of the following AppLocker rule conditions can be used to create rules?' Then Publisher and File hash are both valid conditions. But the stem should be scenario-based. Alternatively, I can change the correct answers to Publisher and File hash, and adjust the scenario to say the administrator needs to allow signed apps and also allow a specific unsigned internal app by hash. That would make both correct. Let me do that. So the stem will be: 'A security administrator is implementing application whitelisting on a fleet of Windows 10 workstations. The administrator wants to use AppLocker to allow only signed applications from trusted publishers to run, and also needs to allow a specific unsigned internal application by its unique file hash. Which TWO of the following AppLocker rule conditions should the administrator use to achieve this? (Choose two.)' Then correct answers are Publisher and File hash. I'll adjust the options accordingly.