Windows 10 computers managed by Intune have users storing files in D:\Folder1. Ensure that only a trusted list of applications is allowed to write to D:\Folder1. Which setting should you enable in the device configuration profile?
Choose an answer
Tap an option to check your answer.
Correct answer: Microsoft Defender Exploit Guard.
Why this is the answer
Microsoft Defender Exploit Guard includes a feature called Controlled Folder Access, which is designed to protect sensitive data from ransomware and other malicious applications by allowing only trusted applications to access protected folders. By configuring Controlled Folder Access, you can specify D:\Folder1 as a protected folder and define the list of applications permitted to write to it. Microsoft Defender Application Guard isolates untrusted websites and Office files in a virtualized container, protecting the host system from potential threats, but it doesn't control write access to local folders. Microsoft Defender SmartScreen provides reputation-based checks for websites and downloaded files, preventing access to malicious content, but it doesn't manage folder write permissions. Microsoft Defender Application Control (formerly Device Guard) is a more comprehensive solution for application whitelisting across the entire system, but Exploit Guard's Controlled Folder Access is the specific feature for protecting designated folders from unauthorized write access.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed