CompTIA Security+ (SY0-701)Security OperationsMedium
A security team is implementing a new endpoint protection solution. They require a tool that provides behavioral analysis, malware detection without relying solely on signatures, and the ability to detect and respond to threats post-compromise. Which solution best fits these requirements?
- ANext-Generation Antivirus (NGAV)
- BTraditional Antivirus (AV)
- CSecurity Information and Event Management (SIEM)
- DNetwork Intrusion Detection System (NIDS)
Show answer & explanationAnswer & explanation
Correct answer: A. Next-Generation Antivirus (NGAV)
Next-Generation Antivirus (NGAV) uses advanced techniques like behavioral analysis, machine learning, and artificial intelligence to detect and prevent both known and unknown threats, often without relying solely on signatures. It also focuses on post-compromise detection and response.
Why the other options are wrong
- B. Traditional Antivirus primarily relies on signature-based detection and lacks advanced behavioral analysis or post-compromise capabilities.
- C. SIEM aggregates and correlates logs from various sources but is not an endpoint protection solution itself.
- D. NIDS monitors network traffic for suspicious activity, not endpoint behavior or file-based malware.
Next-Generation Antivirus (NGAV)
An advanced endpoint protection solution that uses behavioral analysis, machine learning, and AI to detect and prevent both known and unknown threats, often without relying solely on signatures.
- Goes beyond signature-based detection.
- Focuses on behavioral analysis and machine learning.
- Designed to protect against fileless malware and zero-day exploits.
Memory trick: NGAV is like AV's smarter, future-ready kid.