CompTIA Security+ SY0-701 · Simulation Lab

Application Allowlisting with AppLocker

Objective 2.5 · Application allow list Objective 4.1 · Securing computing resources assignmentId splus-applocker-allowlist

Scenario

You are the endpoint security analyst at Briarwood Freight, a regional trucking company. To shrink the attack surface, you are switching the Windows fleet from "run anything" to an allowlist: only software that lives in trusted system locations should be allowed to start, and everything else should be blocked by default.

One line-of-business app breaks that simple rule. The dispatch console RouteDesk.exe runs from C:\LineOfBusiness\RouteDesk\ — outside the protected system folders — and the Dispatchers team needs it. The vendor, Larkspur Logistics Software, LLC, also ships updates roughly monthly, and you do not want to edit policy every time the version number changes.

Working in the Default Domain Policy, complete the three tasks at right.

Policy Console — Default Domain Policy [briarwood.local]

Executable Rules

No rules defined
Action User or group Condition
This rule collection is empty. Start with Create default rules.

Tasks

These check themselves as you work the console.

    Knowledge check

    Four questions on how AppLocker behaves. Pick one answer each.

    Submit your lab

    This label identifies your submission to your instructor. Keep personal info out of it.
    Score 0 / 7

    © 2026 <AUTHOR NAME / ORG> · Original clean-room Security+ lab · assignmentId: splus-applocker-allowlist