CompTIA Security+ (SY0-701)Security OperationsMedium

A security team is implementing a new endpoint protection solution. They require a tool that can not only detect known malware signatures but also identify and block malicious behaviors, even from previously unseen threats. Which type of solution BEST meets these requirements?

  1. ATraditional Antivirus (AV)
  2. BSecurity Information and Event Management (SIEM)
  3. CNext-Generation Antivirus (NGAV)
  4. DIntrusion Detection System (IDS)
Show answer & explanation

Correct answer: C. Next-Generation Antivirus (NGAV)

Next-Generation Antivirus (NGAV) utilizes advanced techniques like machine learning, behavioral analysis, and exploit prevention in addition to signature-based detection to protect against both known and unknown threats.

Why the other options are wrong

  • A. Traditional Antivirus primarily relies on signature-based detection and struggles with unknown or fileless threats.
  • B. A SIEM aggregates and analyzes logs from various sources; it's a monitoring tool, not an endpoint protection solution.
  • D. An IDS monitors network traffic or host-based activity for suspicious patterns but typically doesn't offer endpoint protection or blocking capabilities directly.

Next-Generation Antivirus (NGAV)

An advanced endpoint security solution that uses a variety of techniques beyond traditional signature matching to detect and prevent malware, including unknown and fileless threats.

  • Uses behavioral analysis and machine learning
  • Protects against zero-day threats
  • Often includes exploit prevention

Memory trick: From old AV to new NGAV, endpoints get smarter protection.

More Security Operations questions