CompTIA Security+ (SY0-701)Security OperationsMedium
A SOC is evaluating endpoint protection tools and wants a solution that provides behavioral analysis, automated threat containment, and detailed telemetry for forensic investigation, beyond simple signature matching. Which tool best fits this requirement?
- AData loss prevention agent
- BHost-based firewall
- CEndpoint detection and response (EDR)
- DTraditional signature-based antivirus
Show answer & explanationAnswer & explanation
Correct answer: C. Endpoint detection and response (EDR)
EDR solutions provide continuous behavioral monitoring, automated response actions like isolation, and rich telemetry for forensic investigation, going beyond the static signature matching of traditional antivirus.
Why the other options are wrong
- A. DLP focuses on preventing data exfiltration, not general threat detection and response.
- B. A host-based firewall controls traffic but does not provide behavioral endpoint analytics.
- D. Traditional AV relies mainly on signatures and lacks behavioral analytics and rich telemetry.
Endpoint Detection and Response (EDR)
A security tool that continuously monitors endpoint behavior, detects anomalies, and enables automated response and forensic investigation.
- Goes beyond signature-based detection
- Supports automated isolation/containment
- Provides telemetry for threat hunting and forensics
Memory trick: EDR watches behavior, not just fingerprints.