Cisco Certified Support Technician (CCST) CybersecurityEndpoint SecurityEasy
A security administrator is implementing a new policy for all corporate workstations. The policy dictates that only approved applications from a curated list can be installed and executed, regardless of user privileges. Any attempt to run an unlisted application should be blocked. Which endpoint security technology is best suited to enforce this policy?
- AData Loss Prevention (DLP)
- BEndpoint Detection and Response (EDR)
- CNetwork Access Control (NAC)
- DApplication Whitelisting
Show answer & explanationAnswer & explanation
Correct answer: D. Application Whitelisting
Application Whitelisting is specifically designed to control which applications are allowed to run on an endpoint by maintaining a list of approved software. Any application not on this list is prevented from executing, thus enforcing the policy described.
Why the other options are wrong
- A. DLP is used to prevent sensitive data from leaving the organization's control, not to manage application execution.
- B. EDR focuses on detecting and responding to threats, not primarily on preventing the execution of unapproved applications.
- C. NAC controls network access for devices, not the execution of applications on those devices.
Application Whitelisting
A security measure that allows only approved applications to run on a system, preventing unauthorized or malicious software from executing.
- Prevents execution of unapproved software.
- Enhances security by reducing the attack surface.
- Requires careful management of the approved application list.
Memory trick: Whitelist means 'only good guys allowed in the application club'.