MD-102 Prepare infrastructure for devices Practice Question
Your organization uses Microsoft Intune to manage devices. You need to ensure that only approved applications can run on Windows 10 devices. Which THREE components can you use to implement application control? (Choose three.)
⚠ Common exam trap
Candidates often confuse Windows Information Protection (WIP) with application control because both involve 'policies' in Intune, but WIP is strictly for data loss prevention, not for blocking or allowing application execution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Windows Defender Application Control (WDAC).
Windows Defender Application Control (WDAC) (B) is correct because it is Microsoft's application control technology that enforces code integrity policies on Windows 10, allowing only approved/trusted binaries to execute based on publisher, hash, or file path rules. Intune application control policies (C) are correct because Intune can deploy and manage application control configurations—including WDAC and AppLocker policies—to Windows 10 devices, letting administrators centrally enforce which apps are allowed. AppLocker (D) is correct because it is a built-in Windows 10 application control feature that restricts which applications and files users can run using allow/deny rules based on publisher, path, or hash. Windows Information Protection (A) is not an application control mechanism; it is a data protection feature that helps prevent accidental data leakage by separating and encrypting corporate data, not by blocking unapproved applications. BitLocker (E) is a full-disk encryption feature that protects data at rest, and it has no role in controlling which applications are permitted to run.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Windows Information Protection (WIP).
Why it's wrong here
WIP protects data against leakage by controlling which apps access corporate information, not which applications are permitted to execute. It is tempting because it is an Intune app-related policy, but application control requires AppLocker or Windows Defender Application Control rules that allow or block execution.
- ✓
Windows Defender Application Control (WDAC).
Why this is correct
WDAC is a Windows 10 hypervisor-protected code integrity feature that enforces an explicit allowlist of trusted binaries at the kernel level. Intune deploys WDAC policies as a custom OMA-URI, satisfying the requirement that only approved applications execute on managed devices.
- ✓
Intune application control policies.
Why this is correct
Intune application control policies deliver WDAC or AppLocker configuration through the MDM channel, letting you target device groups and deploy allowlists without Group Policy. This satisfies the requirement to restrict Windows 10 devices to approved applications centrally.
- ✓
AppLocker.
Why this is correct
AppLocker applies rule-based allowlisting to executables, scripts, Windows Installer files and DLLs, and can be deployed via Intune's application control policy. It enforces that only approved applications run, meeting the application control requirement for Windows 10.
- ✗
BitLocker drive encryption.
Why it's wrong here
BitLocker encrypts volumes at rest to protect data if a device is lost or stolen; it does not restrict which applications may execute. It is tempting as a Windows security baseline setting, but application control needs AppLocker or Windows Defender Application Control, which enforce executable allow-lists.
Go deeper
Related to this question
Learn chapter
Implementing App Protection Policies (MAM)
Key term
Microsoft Intune
Microsoft Intune is a cloud-based service that helps organizations manage employee devices, apps, and security policies without needing to own or control the physical hardware.
Key term
Disk encryption
Disk encryption is the process of converting data on a storage device into a coded form that can only be read with the correct decryption key, protecting it from unauthorized access.
About these practice questions
Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.