QuestionQ213

Design security solutions for applications and data

You have a Microsoft 365 subscription and an Azure subscription. Microsoft 365 Defender and Microsoft Defender for Cloud are enabled.

The Azure subscription includes 50 virtual machines. Every virtual machine runs different applications on Windows Server 2019.

You need to recommend a solution that ensures only authorized applications can run on the virtual machines. If an unauthorized application tries to run or be installed, it must be blocked automatically until an administrator authorizes it.

Which security control should you recommend?

  • A app discovery anomaly detection policies in Microsoft Defender for Cloud Apps
  • B Azure Security Benchmark compliance controls in Defender for Cloud
  • C app registrations in Azure AD
  • D application control policies in Microsoft Defender for Endpoint
Explanation

Application control policies enforce an allowlist of trusted code on Windows Server 2019, preventing unapproved applications and installers from executing until they meet an authorized rule. Microsoft documents App Control for Business (WDAC) as restricting which applications and code can run, including support for Windows Server 2019.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!