Courseiva

MD-102 AppLocker Practice Question

A company uses Microsoft Intune to manage Windows 10 devices. They want to prevent users from installing unapproved applications. Which approach provides the most granular control?

⚠ Common exam trap

MD-102 often tests the difference between application control (AppLocker/WDAC) and application management (Intune app deployment); candidates may confuse 'prevent installation' with 'control availability' and pick Store for Business or SmartScreen, which do not provide granular allow-listing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy AppLocker rules via Intune to allow only approved publishers.

AppLocker provides the most granular control because it allows administrators to create rules based on publisher, product name, file name, file version, or file hash, and apply them to specific users or groups. Deployed via Intune, these rules can enforce which applications are allowed to run, effectively blocking unapproved installations. This level of detail (e.g., allowing only signed apps from a specific publisher) is not achievable with the other options.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the Microsoft Store for Business to deploy only approved apps.

    Why it's wrong here

    Microsoft Store for Business restricts Store-sourced deployment, but users can still install unapproved apps from other sources such as sideloaded MSI or EXE files. It is tempting because it curates an approved catalogue, which would be correct if all installation were confined to the Store.

  • ✓

    Deploy AppLocker rules via Intune to allow only approved publishers.

    Why this is correct

    AppLocker rules deployed through Intune let you allow only approved publishers, giving publisher, product name, file name and version-level control over executables, which is more granular than the broader allow or block lists offered by other application control methods.

  • ✗

    Enable Windows Defender SmartScreen to block unknown apps.

    Why it's wrong here

    SmartScreen blocks only executables lacking reputation or a valid signature, so signed or reputable unapproved installers still run; it cannot enforce an allowlist. It is tempting because SmartScreen genuinely filters unknown downloads, which suits blocking malicious software rather than controlling which approved applications users may install.

  • ✗

    Configure User Account Control (UAC) to always notify.

    Why it's wrong here

    UAC always-notify prompts for elevation but users with admin rights can approve the install, so it enforces nothing. UAC suits standard-user elevation prompts; granular control over which applications install requires Intune app protection or Windows Defender Application Control policies.

About these practice questions

This MD-102 question is part of Courseiva's 556-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.