SC-100 Design security solutions for infrastructure Practice Question
Your organization uses Microsoft Intune to manage Windows 10 devices. You need to ensure that only approved applications can run on corporate devices. Which Intune feature should you configure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AppLocker
AppLocker (option D) is the correct choice because it is the Windows feature that lets administrators define and enforce rules specifying which applications users can run on managed devices, and it can be configured and deployed through Intune via an application control policy. This directly satisfies the requirement that only approved applications execute on corporate Windows 10 devices. Windows Defender Firewall (A) controls network traffic by port, protocol, and address, not which local applications are permitted to launch. BitLocker (B) provides full-disk encryption for data-at-rest protection and has no application execution control. Windows Information Protection (C) is designed to separate and protect corporate data from personal data, not to whitelist approved applications for execution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Windows Defender Firewall
Why it's wrong here
Windows Defender Firewall is a host-based network filter that inspects inbound and outbound traffic and applies rule-based allow or block decisions at the network layer. It does not intercept process creation or evaluate executable files before they run, so it cannot prevent an unauthorized application from launching. Firewall rules govern connectivity, not application execution, making it unsuitable for application control.
- ✗
BitLocker
Why it's wrong here
BitLocker Drive Encryption protects data at rest by encrypting the entire volume with AES, preventing offline access to files if the disk is removed or the device is lost. It has no interaction with the OS execution pipeline and does not examine or restrict which programs can be started. BitLocker addresses confidentiality, whereas application control addresses operational security.
- ✗
Windows Information Protection
Why it's wrong here
Windows Information Protection (WIP) is an enterprise data protection feature that labels corporate data and applies policies to prevent copy-paste, drag-drop, or unauthorized sharing into personal apps. WIP does not block an application from executing; it only governs how protected corporate data is accessed and moved. Its purpose is data leakage prevention, not executable-wise enforcement of allowed software.
- ✓
AppLocker
Why this is correct
AppLocker is the correct answer because it enforces application control by creating rules that allow or deny executables, scripts, installers, and DLLs based on file attributes like publisher, product name, file hash, or path. These rules are applied by the AppLocker engine at process initiation, so unauthorized applications are blocked from running. Intune can deploy AppLocker policies via endpoint security and configuration settings, making it a valid application control solution for managed Windows 10 devices.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.