You would do well to put WDAC out of your mind. Microsoft's original software restriction policy (SRP) remains the best, and most capable, version.
AppLocker is Microsoft software restriction policy version 2 (SRPv2) and it is no longer being developed for years. It is in maintenance. Microsoft would get rid of it if it could, but too many enterprises and governments use it, and Microsoft does not want to invoke its big-money-spending clients.
WDAC is Microsoft software restriction policy version 3 (SRPv3) and it is a half-baked messed that is user unfriendly, does not work as intended, does not deploy very well in enterprise and government infrastructure, plus a long list of other issues. Looking at the official WDAC documentation, it appears Microsoft went a bit schizoid with it - not sure or confident of the direction, purpose, or intent of the feature. Way too many ways to do a few things, that only sows confusion and frustration. Then following all that, WDAC doesn't work.
SRPv1 will be shipped in Windows until Microsoft coverts to Apple OS. SRPv1 works, works very well, is easy to use, deploys seamlessly, and most enterprises and governments use it.
@Andy Ful 's Hard_Configurator is all that you need to achieve robust system lockdown - as long as you don't constantly use the Administrator account.
It's your system. Secure it or destroy it if you want to.