Quiz 10 Question 14 of 20

Your SOC enforces a policy that blocks unsigned executables and allows only approved applications on analyst endpoints. An alert shows an attempt to run a new binary is prevented by the policy. Which D3FEND-style defensive technique best describes this control?

Select an answer to reveal the explanation.

Motivation