HOTSPOT
Your network contains an Active Directory domain named contoso.com. All client computers
run Windows 8.
An administrator creates an application control policy and links the policy to an
organizational unit (OU) named OU1. The application control policy contains several deny
rules. The deny rules apply to the Everyone group.
You need to prevent users from running the denied application.
What should you configure?
To answer, select the appropriate object in the answer area.

Explanation:
You should apply an application control policy for executable rules. When AppLocker
policies from various GPOs are merged, both the rules and the enforcement modes are
merged. The most similar Group Policy setting is used for the enforcement mode, and all
rules from linked GPOs are applied.
References:
Exam Ref 70-410: Installing and Configuring Windows Server 2012 R2, Chapter 6: Create
and Manage Group Policy, Objective 6.2: Local Users and Groups, p. 329
http://technet.microsoft.com/en-us/library/dd759115.aspx