SY0-701 exam dumps

SY0-701 practice question 84 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 84

Single answerOperating system (OS)-based

A security administrator needs to harden a fleet of company-issued Windows 11 laptops used by remote employees. The laptops must remain fully usable for normal business tasks, but the administrator wants to reduce the risk of malware persistence, unauthorized software execution, and local credential theft using controls built into the operating system. Which of the following should the administrator implement FIRST to best meet these goals?

  1. A

    Enable BitLocker on all laptops

  2. B

    Implement application allowlisting with Windows Defender Application Control or AppLocker

  3. C

    Disable the local Windows Firewall to reduce user support issues

  4. D

    Grant users local administrator rights so approved software can be installed without IT involvement

Show answer and explanation

Correct answer: B

Explanation

The key phrase is that the organization wants to use operating system-based controls to reduce malware persistence, unauthorized software execution, and local risk on endpoints while maintaining normal business usability. In Windows, application allowlisting through Windows Defender Application Control (WDAC) or AppLocker is a strong OS-based hardening measure because it enforces which applications are permitted to run. This is aligned with Microsoft security baselines and endpoint hardening guidance. BitLocker is also an important Windows OS-based control, but its primary purpose is protecting data at rest rather than controlling execution. Disabling the host firewall or granting local admin rights would weaken security. In practice, this question also reflects the Security+ principle of least privilege and endpoint hardening using native OS controls.

  • A. Incorrect.

    BitLocker is an OS-based security control that protects data at rest by encrypting the drive. It is very valuable for lost or stolen laptops, but it does not primarily address unauthorized software execution or malware persistence during normal operation. It also does not directly mitigate local credential theft in the same way execution control and least-privilege measures do.

  • B. Correct.

    This is the best answer. Application allowlisting is an OS-based hardening control that restricts systems to running only approved executables, scripts, and installers. In Windows environments, Windows Defender Application Control (WDAC) and AppLocker are designed to reduce malware execution, persistence through unauthorized binaries, and user-installed software risk. This directly supports the goal of limiting unauthorized software execution while keeping approved business applications usable.

  • C. Incorrect.

    This is incorrect because the Windows Firewall is an important host-based, OS-native security control. Disabling it would weaken endpoint security and increase exposure to lateral movement and inbound threats. Although it might reduce some support tickets, it does not help with malware persistence, software control, or credential protection.

  • D. Incorrect.

    This is incorrect because granting local administrator rights generally increases risk. Users with administrative privileges can install unapproved software, disable protections, and create persistence mechanisms more easily. It also expands the impact of malware that executes in the user context. This option conflicts with hardening best practices and the principle of least privilege.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam