CompTIA Security+ (SY0-701)Security OperationsEasy

A security team is implementing a new endpoint protection solution. They require a tool that provides behavioral analysis, machine learning capabilities to detect unknown threats, and the ability to isolate compromised endpoints. Which type of solution would best meet these requirements?

  1. ATraditional Antivirus (AV)
  2. BNetwork Intrusion Detection System (NIDS)
  3. CNext-Generation Antivirus (NGAV)
  4. DData Loss Prevention (DLP)
Show answer & explanation

Correct answer: C. Next-Generation Antivirus (NGAV)

Next-Generation Antivirus (NGAV) solutions incorporate advanced techniques like behavioral analysis, machine learning, and artificial intelligence to detect and prevent both known and unknown (zero-day) threats, and often include endpoint isolation capabilities.

Why the other options are wrong

  • A. Traditional AV primarily relies on signature-based detection and lacks advanced behavioral analysis or machine learning for unknown threats.
  • B. NIDS monitors network traffic for suspicious activity, not endpoint behavior or file execution.
  • D. DLP focuses on preventing sensitive data from leaving the organization, not on detecting and preventing malware.

Next-Generation Antivirus (NGAV)

An advanced endpoint security solution that uses AI, machine learning, behavioral analysis, and exploit prevention to detect and prevent known and unknown threats.

  • Goes beyond signature-based detection.
  • Protects against fileless malware and zero-day attacks.
  • Often includes endpoint detection and response (EDR) capabilities.

Memory trick: NGAV is the 'smart' antivirus, learning how threats behave.

More Security Operations questions