exam questions

Exam SC-100 All Questions

View all questions & answers for the SC-100 exam

Exam SC-100 topic 4 question 1 discussion

Actual exam question from Microsoft's SC-100
Question #: 1
Topic #: 4
[All SC-100 Questions]

You have a Microsoft 365 subscription and an Azure subscription. Microsoft 365 Defender and Microsoft Defender for Cloud are enabled.
The Azure subscription contains 50 virtual machines. Each virtual machine runs different applications on Windows Server 2019.
You need to recommend a solution to ensure that only authorized applications can run on the virtual machines. If an unauthorized application attempts to run or be installed, the application must be blocked automatically until an administrator authorizes the application.
Which security control should you recommend?

  • A. app registrations in Azure Active Directory (Azure AD)
  • B. OAuth app policies in Microsoft Defender for Cloud Apps
  • C. Azure Security Benchmark compliance controls in Defender for Cloud
  • D. application control policies in Microsoft Defender for Endpoint
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
PlumpyTumbler
Highly Voted 2 years, 3 months ago
Selected Answer: D
This question has been updated on 8/3/22. Potential answers I'd expect to see are: A. Azure Active Directory (Azure AD) Conditional Access App Control policies B. OAuth app policies in Microsoft Defender for Cloud Apps C. app protection policies in Microsoft Endpoint Manager D. application control policies in Microsoft Defender for Endpoint Notice that only the wrong answers were changed. I'd vote D based on what I know about application control policies. https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/select-types-of-rules-to-create#windows-defender-application-control-policy-rules
upvoted 42 times
PlumpyTumbler
2 years, 3 months ago
My first link was for windows, this is a better resource for cloud based endpoint protection. https://docs.microsoft.com/en-us/mem/configmgr/protect/deploy-use/use-device-guard-with-configuration-manager#what-can-run-when-you-deploy-an-application-control-policy
upvoted 4 times
...
...
rdy4u
Highly Voted 2 years, 3 months ago
The another answer for the same question is "adaptive application controls in Defender for Cloud"
upvoted 18 times
Ramye
11 months, 2 weeks ago
Thx for this. That question is question #23 in Topic 2.
upvoted 1 times
AWSPro24
5 months, 1 week ago
This is scheduled to be deprecated and replaces by Defender for Endpoint features and Defender for Server features https://learn.microsoft.com/en-us/answers/questions/2084852/what-replaces-adaptive-application-control
upvoted 1 times
...
...
...
sherifhamed
Most Recent 1 year, 3 months ago
Selected Answer: D
To ensure that only authorized applications can run on the virtual machines and to block unauthorized applications automatically until an administrator authorizes them, you should recommend: D. Application control policies in Microsoft Defender for Endpoint Microsoft Defender for Endpoint provides application control policies that allow you to define which applications are allowed or blocked on your Windows machines. You can create rules specifying which applications are authorized to run, and any application that doesn't match these rules can be automatically blocked. This provides a strong layer of security and control over the applications running on your virtual machines.
upvoted 5 times
...
AbdallaAM
1 year, 3 months ago
Selected Answer: D
D. application control policies in Microsoft Defender for Endpoint - Microsoft Defender for Endpoint provides a feature known as "Application Control." By using application control policies, you can specify which applications are allowed to run on machines, and all other applications not on the allowed list will be blocked. This feature directly meets the requirement described.
upvoted 1 times
...
Maniact165
1 year, 7 months ago
Selected Answer: D
Its surely D
upvoted 2 times
...
zellck
1 year, 7 months ago
Selected Answer: D
D is the answer. https://learn.microsoft.com/en-us/mem/configmgr/protect/deploy-use/use-device-guard-with-configuration-manager prevents malicious code from running by ensuring that only approved code, that you know, can be run. Application Control is a software-based security layer that enforces an explicit list of software that is allowed to run on a PC. On its own, Application Control doesn't have any hardware or firmware prerequisites. Application Control policies deployed with Configuration Manager enable a policy on devices in targeted collections that meet the minimum Windows version and SKU requirements outlined in this article. Optionally, hypervisor-based protection of Application Control policies deployed through Configuration Manager can be enabled through group policy on capable hardware.
upvoted 1 times
zellck
1 year, 7 months ago
Gotten this in May 2023 exam.
upvoted 2 times
...
...
awssecuritynewbie
1 year, 10 months ago
Selected Answer: D
for sure D. MDE can implement security application policy controls to prevent installation of an application.
upvoted 1 times
...
dbhagz
1 year, 10 months ago
Selected Answer: D
https://learn.microsoft.com/en-us/mem/configmgr/protect/deploy-use/use-device-guard-with-configuration-manager
upvoted 1 times
...
Mo22
1 year, 10 months ago
Selected Answer: D
Microsoft Defender for Endpoint provides application control policies which allow administrators to define what applications are allowed to run on virtual machines, and block any unauthorized applications from running. This helps to ensure that only authorized applications can run on the virtual machines and improve the overall security posture of the environment. If an unauthorized application attempts to run or be installed, it will be blocked automatically until an administrator authorizes the application.
upvoted 1 times
...
examdog
1 year, 10 months ago
Selected Answer: D
The link shows that Defender for EndPoint is available for virtual machines and is recommended to be used with Defender for Cloud. https://learn.microsoft.com/en-us/azure/defender-for-cloud/integration-defender-for-endpoint
upvoted 2 times
...
[Removed]
2 years ago
Selected Answer: D
"Application Control lets you strongly control what can run on devices you manage. This feature can be useful for devices in high-security departments, where it's vital that unwanted software can't run." Enable "Enforcement enabled" so that only trusted executables are allowed to run. https://learn.microsoft.com/en-us/mem/configmgr/protect/deploy-use/use-device-guard-with-configuration-manager
upvoted 1 times
...
Learner2022
2 years ago
Selected Answer: B
Defender for Endpoint does not include server licenses. D is incorrect.
upvoted 1 times
Toschu
1 year, 9 months ago
The product is called "Defender for Servers"
upvoted 1 times
...
buguinha
1 year, 10 months ago
Defender for Endpoint can be installed on Server Platforms
upvoted 1 times
...
...
TP447
2 years ago
Answer is Defender for Endpoint Server so D
upvoted 1 times
...
ksksilva2022
2 years, 1 month ago
Selected Answer: D
https://learn.microsoft.com/en-us/defender-cloud-apps/app-permission-policy
upvoted 1 times
...
monkeybiznex
2 years, 2 months ago
Oauth... LOL!
upvoted 2 times
...
Granwizzard
2 years, 3 months ago
Selected Answer: D
I agree with D. We could also use: https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/detect-block-potentially-unwanted-apps-microsoft-defender-antivirus?view=o365-worldwide Microsoft Defender for Endpoint is my choice.
upvoted 2 times
...
lummer
2 years, 3 months ago
Certainly D. https://docs.microsoft.com/en-us/defender-cloud-apps/governance-discovery#block-apps-with-defender-for-endpoint
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...