CompTIA Security+ (SY0-701)Security OperationsEasy

A security administrator needs to ensure that only authorized applications are allowed to execute on critical servers, preventing unknown or malicious software from running. Which security control would best achieve this goal?

  1. AAntivirus software
  2. BIntrusion Prevention System (IPS)
  3. CApplication whitelisting
  4. DData Loss Prevention (DLP)
Show answer & explanation

Correct answer: C. Application whitelisting

Application whitelisting explicitly permits only a predefined list of authorized applications to run, effectively blocking all others. This directly addresses the requirement of preventing unknown or malicious software from executing.

Why the other options are wrong

  • A. Antivirus software attempts to detect and remove malicious software, but it relies on signatures or heuristics and may not catch all unknown threats.
  • B. An IPS monitors network traffic for malicious activity and can block it, but it does not control what applications execute on endpoints.
  • D. DLP solutions prevent sensitive data from leaving the organization, which is unrelated to controlling application execution.

Application Whitelisting

A security control that allows only a predefined, approved list of applications to execute on a system, blocking all other (unauthorized) applications.

  • Highly effective against unknown malware and zero-day exploits.
  • Reduces the attack surface by preventing unauthorized code execution.
  • Requires careful management of the approved application list.

Memory trick: Whitelist: Only the 'white' (approved) list gets to play.

More Security Operations questions