QuestionQ256

Design security solutions for infrastructure

You have a Microsoft 365 subscription and an Azure subscription. Microsoft 365 Defender and Microsoft Defender for Cloud are enabled.

The Azure subscription includes 50 virtual machines. Every virtual machine runs different applications on Windows Server 2019.

You need to recommend a solution that ensures only authorized applications can run on the virtual machines. If an unauthorized application tries to run or be installed, it must be blocked automatically until an administrator authorizes the application.

Which security control should you recommend?

  • A app registrations in the Microsoft Entra tenant
  • B OAuth app policies in Microsoft Defender for Cloud Apps
  • C app protection policies in Microsoft Endpoint Manager
  • D application control policies in Microsoft Defender for Endpoint
Explanation

Application control policies enforce an explicit allowlist of software permitted to run. On Windows Server 2019, App Control policies can block unapproved executables and scripts until an administrator updates the policy to authorize them; Defender for Endpoint can centrally support policy monitoring and management.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!