CompTIA Security+ (SY0-701)Security OperationsEasy
A security team is implementing a new endpoint protection solution. They require a tool that provides behavioral analysis, machine learning capabilities to detect unknown threats, and the ability to isolate compromised endpoints. Which type of solution would best meet these requirements?
- ATraditional Antivirus (AV)
- BNetwork Intrusion Detection System (NIDS)
- CNext-Generation Antivirus (NGAV)
- DData Loss Prevention (DLP)
Show answer & explanationAnswer & explanation
Correct answer: C. Next-Generation Antivirus (NGAV)
Next-Generation Antivirus (NGAV) solutions incorporate advanced techniques like behavioral analysis, machine learning, and artificial intelligence to detect and prevent both known and unknown (zero-day) threats, and often include endpoint isolation capabilities.
Why the other options are wrong
- A. Traditional AV primarily relies on signature-based detection and lacks advanced behavioral analysis or machine learning for unknown threats.
- B. NIDS monitors network traffic for suspicious activity, not endpoint behavior or file execution.
- D. DLP focuses on preventing sensitive data from leaving the organization, not on detecting and preventing malware.
Next-Generation Antivirus (NGAV)
An advanced endpoint security solution that uses AI, machine learning, behavioral analysis, and exploit prevention to detect and prevent known and unknown threats.
- Goes beyond signature-based detection.
- Protects against fileless malware and zero-day attacks.
- Often includes endpoint detection and response (EDR) capabilities.
Memory trick: NGAV is the 'smart' antivirus, learning how threats behave.