Study. uk . com
  1. Home
  2. All questions
  3. Question 224

CompTIA Security+ study material · question 224 of 611

What is the structural weakness of a deny-listing approach to software control?

  1. It requires code signing to function
  2. It cannot be applied to scripts
  3. Anything not yet on the list is permitted to run
  4. It requires more administrative effort than allow-listing
Show the answer

Answer: C. Anything not yet on the list is permitted to run

Deny-listing is easier to operate but always trails the attacker, because the list must name the threat first.

Challenge yourself on this topic → Study as cards