Question 1
A security architect is designing a Symantec Endpoint Security (SES) Complete policy for a group of developers who frequently use unsigned, custom-compiled executables for testing. The CISO has mandated that Application Control must be enabled in blacklist mode for all workstations, but developer productivity should not be impeded. Which policy configuration provides the most secure and efficient solution to meet these conflicting requirements?
Answer and explanation
Correct answer: D
This is the most secure and scalable solution. Using a trusted publisher certificate allows developers to sign their own compiled code, which Application Control will then trust. This avoids the insecurity of path-based exceptions (where malware could be placed), the potential over-permission of allowing any process from an IDE, and the administrative nightmare of constantly updating file hashes every time the code is recompiled.