Courseiva
Prepare infrastructure for devicesmediumMultiple ChoiceObjective-mapped

MD-102 Windows Defender Application Control Practice Question

Your organization recently deployed Windows 11 devices managed by Microsoft Intune. You need to ensure that only approved third-party drivers are installed on these devices. What is the best approach?

⚠ Common exam trap

Candidates often assume that blocking driver updates from Windows Update is sufficient, but this does not prevent manual installation or side-loading of drivers. WDAC provides a stronger control by enforcing code integrity at installation time.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure a Windows Defender Application Control policy to block unsigned drivers.

Windows Defender Application Control (WDAC) allows you to configure code integrity policies that restrict driver installation to only those that are signed by approved publishers or have known-good hashes. This ensures that only approved third-party drivers, as defined by your organization's policy, can be installed, regardless of the installation source (Windows Update, manual, or otherwise). Option C is insufficient because blocking driver updates from Windows Update does not prevent manual installation of unapproved drivers. Options A and B do not provide a comprehensive enforcement mechanism for driver approval.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Deploy a Windows Driver Frameworks (WDF) Coinstaller to enforce driver signing.

    Why it's wrong here

    Incorrect. A Windows Driver Frameworks (WDF) Coinstaller is used to install driver packages, not to enforce which drivers are approved. It does not restrict installation to approved drivers.

  • Use Device Installation Restrictions to allow only approved hardware IDs.

    Why it's wrong here

    Incorrect. Device Installation Restrictions can block installation of devices with specific hardware IDs, but they do not provide a method to define 'approved third-party drivers' at the driver level. They focus on hardware rather than driver trust.

  • Configure Windows Update for Business group policy settings to block driver updates from Windows Update.

    Why it's wrong here

    Incorrect. While blocking driver updates from Windows Update prevents automatic updates, it does not prevent manually initiated driver installations (e.g., via .inf files or third-party tools). Thus, it does not ensure only approved drivers are installed.

  • Configure a Windows Defender Application Control policy to block unsigned drivers.

    Why this is correct

    Correct. Windows Defender Application Control (WDAC) enforces a code integrity policy that allows only drivers signed by trusted publishers or with specific hashes to install. This ensures that only approved third-party drivers can be installed, regardless of the source.

About these practice questions

One of 942 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.