Diff of WDAC block list. One will BSOD Windows because it has no FileAttrib restrictions on Microsoft Windows Third Party Component CA 2012 signer. The other will NOT BSOD Windows because it has FileAttrib restrictions on Microsoft Windows Third Party Component CA 2012 signer. But it also will not block the driver unless HVCI is on.
https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/117/468/366/710/281/original/0dd79c9b462e187d.png