CompTIA Security+ (SY0-701)Security OperationsMedium

A security team is implementing new endpoint protection. They require a tool that provides advanced threat detection capabilities beyond traditional signature-based antivirus, including behavioral analysis, machine learning for unknown threats, and the ability to detect fileless malware. Which solution BEST meets these requirements?

  1. AEndpoint Detection and Response (EDR)
  2. BSecurity Information and Event Management (SIEM)
  3. CNetwork Intrusion Prevention System (NIPS)
  4. DTraditional Antivirus (AV)
Show answer & explanation

Correct answer: A. Endpoint Detection and Response (EDR)

Endpoint Detection and Response (EDR) solutions are designed to go beyond traditional antivirus by providing continuous monitoring, behavioral analysis, machine learning for anomaly detection, and the ability to detect advanced threats like fileless malware on endpoints.

Why the other options are wrong

  • B. SIEM aggregates and correlates logs from various sources but doesn't provide endpoint-specific advanced threat detection and behavioral analysis capabilities itself.
  • C. NIPS monitors network traffic, not individual endpoint behavior or fileless malware directly on the endpoint.
  • D. Traditional AV primarily relies on signature-based detection and lacks the advanced behavioral and machine learning capabilities for unknown and fileless threats.

Endpoint Detection and Response (EDR)

An integrated endpoint security solution that continuously monitors and collects data from endpoint devices, providing advanced threat detection, investigation, and response capabilities.

  • Goes beyond traditional antivirus.
  • Uses behavioral analysis and machine learning.
  • Detects fileless malware and advanced persistent threats.

Memory trick: For 'Enhanced Detection and Response' on endpoints, you need 'EDR'.

More Security Operations questions