MD-102 Windows Defender Application Control Practice Question
Your organization recently deployed Windows 11 devices managed by Microsoft Intune. You need to ensure that only approved third-party drivers are installed on these devices. What is the best approach?
⚠ Common exam trap
Candidates often assume that blocking driver updates from Windows Update is sufficient, but this does not prevent manual installation or side-loading of drivers. WDAC provides a stronger control by enforcing code integrity at installation time.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a Windows Defender Application Control policy to block unsigned drivers.
Windows Defender Application Control (WDAC) allows you to configure code integrity policies that restrict driver installation to only those that are signed by approved publishers or have known-good hashes. This ensures that only approved third-party drivers, as defined by your organization's policy, can be installed, regardless of the installation source (Windows Update, manual, or otherwise). Option C is insufficient because blocking driver updates from Windows Update does not prevent manual installation of unapproved drivers. Options A and B do not provide a comprehensive enforcement mechanism for driver approval.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy a Windows Driver Frameworks (WDF) Coinstaller to enforce driver signing.
Why it's wrong here
Incorrect. A Windows Driver Frameworks (WDF) Coinstaller is used to install driver packages, not to enforce which drivers are approved. It does not restrict installation to approved drivers.
- ✗
Use Device Installation Restrictions to allow only approved hardware IDs.
Why it's wrong here
Incorrect. Device Installation Restrictions can block installation of devices with specific hardware IDs, but they do not provide a method to define 'approved third-party drivers' at the driver level. They focus on hardware rather than driver trust.
- ✗
Configure Windows Update for Business group policy settings to block driver updates from Windows Update.
Why it's wrong here
Incorrect. While blocking driver updates from Windows Update prevents automatic updates, it does not prevent manually initiated driver installations (e.g., via .inf files or third-party tools). Thus, it does not ensure only approved drivers are installed.
- ✓
Configure a Windows Defender Application Control policy to block unsigned drivers.
Why this is correct
Correct. Windows Defender Application Control (WDAC) enforces a code integrity policy that allows only drivers signed by trusted publishers or with specific hashes to install. This ensures that only approved third-party drivers can be installed, regardless of the source.
Go deeper
Related to this question
Learn chapter
Introduction to Endpoint Management in Microsoft 365
Key term
Windows 11
Windows 11 is Microsoft's latest desktop operating system, offering a redesigned interface, enhanced security features, and improved support for modern hardware.
Key term
Microsoft Intune
Microsoft Intune is a cloud-based service that helps organizations manage employee devices, apps, and security policies without needing to own or control the physical hardware.
About these practice questions
One of 942 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.