You operate a group of Windows Server web servers running a custom app from D:\Apps. You want to initially observe allowed processes, then enforce an allowlist that includes the custom app’s path, using Microsoft Defender for Cloud. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: In Defender for Cloud, enable Adaptive application controls for the machine‑learning “Web servers” group, keep it in Audit mode to review suggestions, add a custom path rule for D:\Apps\*.exe, then switch the group to Enforce mode..
Why this is the answer
The correct option leverages Defender for Cloud's Adaptive application controls, which are designed for this scenario. Enabling them for the "Web servers" group allows Defender for Cloud to automatically learn and suggest allowed applications. Starting in Audit mode is crucial for reviewing these suggestions and identifying legitimate applications before enforcement. Adding a custom path rule for D:\Apps\.exe specifically allows your custom application. Finally, switching to Enforce mode applies the allowlist. Incorrect options: Group Policy with WDAC is a valid application control method but is not managed through Defender for Cloud and doesn't directly address the requirement for initial observation and machine learning. AppLocker is a legacy application control solution, and manually configuring it on each server is less scalable and doesn't integrate with Defender for Cloud's adaptive capabilities. Azure Policy is for managing and enforcing cloud resource configurations, not for granular process control within a server's operating system. Disabling machine learning and forcing a "Deny" policy is overly restrictive and would likely block legitimate system processes, causing service disruption.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed