CompTIA Security+ (SY0-701)Security OperationsEasy

A security administrator needs to ensure that only authorized applications are allowed to execute on corporate workstations. Any attempt to run an unauthorized executable should be blocked. Which security control should be implemented?

  1. AEndpoint Detection and Response (EDR)
  2. BHost-based Intrusion Detection System (HIDS)
  3. CData Loss Prevention (DLP)
  4. DApplication Whitelisting
Show answer & explanation

Correct answer: D. Application Whitelisting

Application whitelisting is a security measure that allows only pre-approved applications to run on a system, effectively blocking all unauthorized executables. This directly addresses the requirement.

Why the other options are wrong

  • A. EDR provides advanced detection and response capabilities but application whitelisting is a more direct and preventative control for this specific requirement.
  • B. A HIDS detects suspicious activity on a host but doesn't inherently block unauthorized applications from running.
  • C. DLP prevents sensitive data from leaving the organization, not controlling application execution.

Application Whitelisting

A security approach that allows only an explicitly approved list of applications to execute on a system, blocking all others by default.

  • Highly effective against malware
  • Reduces attack surface
  • Can be complex to manage in dynamic environments

Memory trick: Only good apps get a green light.

More Security Operations questions