StudyToCert

All certifications / Security+ / Lessons

CompTIA Security+ SY0-701 · Domain 2: Threats, vulnerabilities & mitigations

Application allow listing

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Application allow listing (formerly called whitelisting) permits only approved software to run on a system and blocks everything else by default. It flips the traditional antivirus model. Antivirus uses a deny list: it tries to recognize known-bad programs and blocks them, which means brand-new malware, custom tools and many fileless techniques can slip through. An allow list instead asks 'is this program known and approved?' and refuses anything that is not, whether or not anyone has seen it before. That makes it one of the most effective controls against ransomware and unauthorized software. Government and industry security guidance consistently lists it among the highest-value defensive measures, precisely because it does not depend on recognizing the attacker's tools.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study Security+ for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Security+ study plan