HOTSPOT
Your network contains an Active Directory forest. The forest contains a single domain named
contoso.com.
AppLocker policies are enforced on all member servers.
You view the AppLocker policy applied to the member servers as shown in the exhibit.(Click
the Exhibit button.)
To answer, complete each statement according to the information presented in the
exhibit.Each correct selection is worth one point.

This is confusing question, because all users (including admins) by default are members of Domain Users group, but Domain Admins group isn’t member of Domain Users group.
Deny rule supersedes Allow rule.
I will go for Only local users.
0
0
I agree here. If someone can give us a better answer please do.
0
0
When i first read the question i chose: “Only members of Domain Admins” and “Everyone”, but after reading your posts i decided to try this in my lab, since i wanted to clarify this.
I tried it in my lab and i confirmed that the administrator account wasn’t able to run Internet Explorer just like any other domain user.
So now, my final answer, and the correct answer is:
– Only local users
– Everyone
If you’re still unsure, you’re welcome to try, just like i did.
1
0
The domain admin is not default a member of the domain users right 🙂
0
0
No the server admins group is not a member of the domain user group, but the members within the group server admins are all members of the domain users group.
0
0
I guess it is assumed that the users in the Domain admin group have been removed from Domain users.
0
0
Not, but all users accounts are members.
“Domain Users
The Domain Users group includes all user accounts in a domain. When you create a user account in a domain, it is automatically added to this group.”
https://technet.microsoft.com/en-us/library/dn579255.aspx#BKMK_DomainUsers
about domain admins:
https://technet.microsoft.com/en-us/library/dn579255.aspx#BKMK_DomainAdmins
0
0
Windows Mail is not present on windows servers, so “No one can run Windows Mail on the
servers.”
At the exam Windows Mail was changed with Wordpad. So “Everyone can run Wordpad on the
servers”.
0
0
This is from Microsoft
Domain Users
This group contains all domain users. By default, any user account created in the domain becomes a member of this group automatically. This group can be used to represent all users in the domain. For example, if you want all domain users to have access to a printer, you can assign permissions for the printer to this group (or add the Domain Users group to a local group, on the print server, that has permissions for the printer).
So Domain Admins are member of Domain Users
So it’s
Local Users
Everyone
0
0