You must prevent unsigned code from running on Windows Server 2022 file servers, allow only Microsoft-signed and Contoso-signed binaries/drivers, and begin in audit mode for a week before enforcing. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a Windows Defender Application Control base policy (multiple-policy format) allowing Microsoft and Contoso publisher rules, set the policy to Enabled: Audit Mode, convert to a binary (.cip), deploy it to C:\Windows\System32\CodeIntegrity\CiPolicies\Active, then switch to enforcement after validation..
Why this is the answer
The correct solution is to create a Windows Defender Application Control (WDAC) base policy. WDAC is designed for strict code integrity, allowing specific publishers (Microsoft and Contoso in this case) and preventing unsigned code. The multiple-policy format is suitable for combining rules. Starting in audit mode is crucial for testing without immediate impact, and deploying the .cip file to the specified directory activates the policy. After a week of auditing, the policy can be switched to enforcement. AppLocker is less robust for kernel-mode code integrity and driver control compared to WDAC. SmartScreen and Reputation-based protection are client-side features and not designed for server-wide, granular code integrity enforcement. Software Restriction Policies (SRP) are an older technology, less flexible, and not as effective as WDAC for modern code integrity requirements, especially for drivers.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed