One way to do it is to whitelist all binaries in the system, and sandbox all applications (to prevent chances of a malicious PDF/image/etc abusing a buggy application).
Note that there may be still ways to bypass it if you're an attacker sitting at the computer, rather than a hapless user.