ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 291 - CAS-004 discussion

Report
Export

A company has decided that only administrators are permitted to use PowerShell on their Windows computers. Which of the following is the BEST way for an administrator to implement this decision?

A.
Monitor the Application and Services Logs group within Windows Event Log.
Answers
A.
Monitor the Application and Services Logs group within Windows Event Log.
B.
Uninstall PowerSheII from all workstations.
Answers
B.
Uninstall PowerSheII from all workstations.
C.
Configure user settings in Group Policy.
Answers
C.
Configure user settings in Group Policy.
D.
Provide user education and training.
Answers
D.
Provide user education and training.
E.
Block PowerSheII via HIDS.
Answers
E.
Block PowerSheII via HIDS.
Suggested answer: C

Explanation:

Configuring user settings in Group Policy is the best way for an administrator to implement the decision to restrict PowerShell access to only administrators. Group Policy is a feature of Windows that allows administrators to manage and enforce settings for users and computers in a domain. By using Group Policy, an administrator can create a policy that blocks or disables PowerShell for all users except for a particular group, such as administrators. This policy can be applied to all computers in the domain or to specific organizational units. This method is more effective and manageable than uninstalling PowerShell, monitoring event logs, providing user education, or blocking PowerShell via HIDS. Verified

Reference:

https://www.windowscentral.com/how-disable-powershell-windows-10

https://learn.microsoft.com/en-us/answers/questions/195218/how-to-restrict-powershell-for-all-users-except-fo

https://windowsloop.com/block-disable-powershell/

asked 02/10/2024
Christian Galea
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first