CompTIA Security+ (SY0-701)Security OperationsMedium
A security team is implementing new endpoint protection. They require a tool that provides continuous monitoring of endpoint activities, records all system events, and allows security analysts to perform advanced threat hunting and incident investigation across all managed devices. Which solution best fits these requirements?
- ANetwork Access Control (NAC)
- BEndpoint Detection and Response (EDR)
- CSecurity Information and Event Management (SIEM)
- DNext-Generation Antivirus (NGAV)
Show answer & explanationAnswer & explanation
Correct answer: B. Endpoint Detection and Response (EDR)
Endpoint Detection and Response (EDR) solutions are specifically designed to continuously monitor endpoint activity, collect and store detailed event data, and provide tools for security analysts to detect, investigate, and respond to threats across an organization's endpoints. This aligns perfectly with continuous monitoring, event recording, and threat hunting capabilities.
Why the other options are wrong
- A. NAC controls network access based on device posture and user authentication, not continuous endpoint monitoring and threat hunting.
- C. SIEM aggregates logs from many sources (including endpoints) but doesn't provide the granular, real-time endpoint visibility and control of an EDR.
- D. NGAV focuses on preventing malware execution but typically lacks the deep investigative and threat hunting capabilities across all endpoints.
Endpoint Detection and Response (EDR)
A security solution that continuously monitors and collects data from endpoint devices, enabling comprehensive threat detection, investigation, and response capabilities.
- Provides deep visibility into endpoint activity (processes, file changes, network connections).
- Supports threat hunting and forensic analysis.
- Allows for rapid response actions like isolating compromised devices.
Memory trick: EDR is the 'Endpoint Detective' watching everything.