exam questions

Exam CSCP All Questions

View all questions & answers for the CSCP exam

Exam SC-100 topic 4 question 23 discussion

Actual exam question from APICS's CSCP
Question #: 23
Topic #: 1
[All CSCP Questions]

You have a Microsoft 365 subscription and an Azure subscription. Microsoft 365 Defender and Microsoft Defender for Cloud are enabled.

The Azure subscription contains 50 virtual machines. Each virtual machine runs different applications on Windows Server 2019.

You need to recommend a solution to ensure that only authorized applications can run on the virtual machines. If an unauthorized application attempts to run or be installed, the application must be blocked automatically until an administrator authorizes the application.

Which security control should you recommend?

  • A. OAuth app policies in Microsoft Defender for Cloud Apps
  • B. Azure Security Benchmark compliance controls in Defender for Cloud
  • C. application control policies in Microsoft Defender for Endpoint
  • D. app discovery anomaly detection policies in Microsoft Defender for Cloud Apps
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
subratasen
9 months, 2 weeks ago
For this specific question I prefer to answer 'OAuth app policies in Microsoft Defender for Cloud Apps' if there is any such option available; based on Microsoft reference. Reference: https://learn.microsoft.com/en-us/defender-cloud-apps/app-permission-policy "You can set the policy based on the group memberships of the users who authorized the apps. For example, an admin can decide to set a policy that revokes uncommon apps if they ask for high permissions, only if the user who authorized the permissions is a member of the Administrators group." However I found same question several times when this option is not at all available. In that case, I would go with 'application control policies in Microsoft Defender for Endpoint' or 'adaptive application controls in Defender for Cloud'. Suggestion please.
upvoted 1 times
...
subratasen
9 months, 2 weeks ago
Adaptive application controls of Microsoft Defender for Cloud improve compliance with local security policies that dictate the use of only licensed software. However key condition is in the question 'If an unauthorized application attempts to run or to be installed the application must be blocked automatically until an administrator authorizes the application' in question. Reference: https://learn.microsoft.com/en-us/defender-cloud-apps/app-permission-policy "You can set the policy based on the group memberships of the users who authorized the apps. For example, an admin can decide to set a policy that revokes uncommon apps if they ask for high permissions, only if the user who authorized the permissions is a member of the Administrators group." And Defender for Cloud Apps is part of Azure 365 Defender. Therefore it should be A
upvoted 1 times
...
Ramye
11 months, 1 week ago
This is the 5th time this question is listed and the answer for this occurrence is different than other ones.
upvoted 1 times
...
sherifhamed
1 year, 3 months ago
Selected Answer: C
C. Application control policies in Microsoft Defender for Endpoint Application control policies, also known as application whitelisting, allow you to specify which applications are authorized to run on your virtual machines and block all others. If an unauthorized application attempts to run, it will be blocked until an administrator authorizes it. This control provides a strong layer of security against unapproved or potentially malicious applications. The other options (A, B, and D) are not primarily designed for controlling which applications can run on Windows Server virtual machines in your Azure subscription
upvoted 1 times
...
ServerBrain
1 year, 4 months ago
Selected Answer: A
With answer C, i do not see where there is reference indicating admin approval for blocked apps. A is the answer: https://learn.microsoft.com/en-us/defender-cloud-apps/app-permission-policy
upvoted 1 times
...
zellck
1 year, 7 months ago
Selected Answer: C
C is the answer. https://learn.microsoft.com/en-us/mem/configmgr/protect/deploy-use/use-device-guard-with-configuration-manager prevents malicious code from running by ensuring that only approved code, that you know, can be run. Application Control is a software-based security layer that enforces an explicit list of software that is allowed to run on a PC. On its own, Application Control doesn't have any hardware or firmware prerequisites. Application Control policies deployed with Configuration Manager enable a policy on devices in targeted collections that meet the minimum Windows version and SKU requirements outlined in this article. Optionally, hypervisor-based protection of Application Control policies deployed through Configuration Manager can be enabled through group policy on capable hardware.
upvoted 2 times
...
KallMeDan
1 year, 7 months ago
This is the other version of the same question I have seen and the answer was A: "You have a Microsoft 365 subscription and an Azure subscription. Microsoft 365 Defender and Microsoft Defender for Cloud are enabled. The Azure subscription contains 50 virtual machines. Each virtual machine runs different applications on Windows Server 2019. You need to recommend a solution to ensure that only authorized applications can run on the virtual machines. If an unauthorized application attempts to run or be installed, the application must be blocked automatically until an administrator authorizes the application. Which security control should you recommend? A. adaptive application controls in Defender for Cloud B. app protection policies in Microsoft Endpoint Manager C. OAuth app policies in Microsoft Defender for Cloud Apps D. Azure Active Directory (Azure AD) Conditional Access App Control policies"
upvoted 2 times
...
Gurulee
1 year, 9 months ago
Selected Answer: C
App Control for apps on endpoints. Whereas, oauth policies allow you to ban/disable Azure Cloud Enterprise Applications.
upvoted 1 times
...
Gurulee
1 year, 9 months ago
Selected Answer: C
Application Control lets you strongly control what can run on devices you manage. This feature can be useful for devices in high-security departments, where it's vital that unwanted software can't run.
upvoted 1 times
...
God2029
1 year, 9 months ago
It is C
upvoted 1 times
...
awssecuritynewbie
1 year, 10 months ago
Selected Answer: C
C 4 sure
upvoted 1 times
...
buguinha
1 year, 10 months ago
Selected Answer: C
C is the correct. MDCA does not control the servers. Microsoft Defender does
upvoted 1 times
...
MKnight25
1 year, 10 months ago
Selected Answer: C
Application control is the correct answer.
upvoted 3 times
...
dbhagz
1 year, 10 months ago
Selected Answer: C
Application Control is a software-based security layer that enforces an explicit list of software that is allowed to run on a PC https://learn.microsoft.com/en-us/mem/configmgr/protect/deploy-use/use-device-guard-with-configuration-manager
upvoted 3 times
...
tech_rum
1 year, 10 months ago
C is the correct answer
upvoted 1 times
...
Ssasid
1 year, 10 months ago
Its C Application control policies https://learn.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/wdac-and-applocker-overview
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...