SY0-701 exam dumps

SY0-701 practice question 130 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 130

Single answerApplication allow list

A hospital's security team is responding to several malware incidents caused by users downloading unauthorized utilities and running portable executables from their Downloads folders and USB drives. The organization must allow only approved applications to run on Windows workstations while minimizing disruption to clinical staff who need access to a small set of sanctioned medical software. Which solution would BEST meet this requirement?

  1. A

    Deploy an application allow list that permits only approved executables, scripts, installers, and libraries to run, with rules based on trusted publishers or approved file paths/hashes

  2. B

    Deploy host-based antivirus and configure it to automatically quarantine any file that matches known malware signatures

  3. C

    Require all users to authenticate with multifactor authentication before launching applications

  4. D

    Enable full-disk encryption on all workstations to prevent unauthorized programs from executing

Show answer and explanation

Correct answer: A

Explanation

The best answer is to deploy an application allow list, because the requirement is to allow only approved software to run and block everything else by default. This is a preventive control that directly addresses unauthorized utilities, portable executables, and software launched from user-writable locations such as Downloads folders and removable media. In Windows environments, common enterprise approaches include application control technologies that enforce allow rules using file hash, path, or digital signature/publisher information. Security best practices from organizations such as NIST emphasize application control/allow listing as an effective method for reducing malware execution and unauthorized software use, especially on systems requiring a stable and limited software set. Compared with antivirus, MFA, or disk encryption, allow listing is the only option that directly enforces approved application execution.

  • A. Correct.

    Correct. An application allow list is specifically designed to prevent unauthorized software from executing by allowing only explicitly approved applications. In this scenario, it addresses the core problem: users running portable tools and unauthorized executables from locations such as Downloads folders and USB drives. Using publisher, path, or hash-based rules is a common implementation approach. Publisher rules can reduce administrative overhead for signed software updates, while path or hash rules can be used for tightly controlled applications. This is aligned with Security+ objectives around application control and limiting execution to trusted software.

  • B. Incorrect.

    Incorrect. Host-based antivirus is useful for detecting and blocking known malicious files, but it does not fully solve the problem of unauthorized yet not-yet-malicious software being executed. Portable admin tools, unsanctioned remote access clients, or custom binaries may not match malware signatures and could still run. This option reflects the common misconception that antivirus alone provides the same preventive control as application allow listing.

  • C. Incorrect.

    Incorrect. Multifactor authentication strengthens access control for user authentication, but it does not determine which applications are permitted to execute after the user signs in. A user could still launch unauthorized software if execution controls are not in place. Someone might choose this option because MFA is a strong security control, but it addresses identity assurance, not application execution control.

  • D. Incorrect.

    Incorrect. Full-disk encryption protects data at rest, such as on lost or stolen devices, but it does not stop a logged-in user from launching unauthorized applications. This distractor is plausible because encryption is an important endpoint control, but it is unrelated to enforcing which programs may run during normal operation.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam