CompTIA Security+ (SY0-701)Security OperationsMedium
A security team is implementing a new endpoint protection solution. They require a tool that can not only detect known malware signatures but also identify and block malicious behaviors, even from previously unseen threats. Which type of solution BEST meets these requirements?
- ATraditional Antivirus (AV)
- BSecurity Information and Event Management (SIEM)
- CNext-Generation Antivirus (NGAV)
- DIntrusion Detection System (IDS)
Show answer & explanationAnswer & explanation
Correct answer: C. Next-Generation Antivirus (NGAV)
Next-Generation Antivirus (NGAV) utilizes advanced techniques like machine learning, behavioral analysis, and exploit prevention in addition to signature-based detection to protect against both known and unknown threats.
Why the other options are wrong
- A. Traditional Antivirus primarily relies on signature-based detection and struggles with unknown or fileless threats.
- B. A SIEM aggregates and analyzes logs from various sources; it's a monitoring tool, not an endpoint protection solution.
- D. An IDS monitors network traffic or host-based activity for suspicious patterns but typically doesn't offer endpoint protection or blocking capabilities directly.
Next-Generation Antivirus (NGAV)
An advanced endpoint security solution that uses a variety of techniques beyond traditional signature matching to detect and prevent malware, including unknown and fileless threats.
- Uses behavioral analysis and machine learning
- Protects against zero-day threats
- Often includes exploit prevention
Memory trick: From old AV to new NGAV, endpoints get smarter protection.