Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsMedium

A security team is implementing a new endpoint detection and response (EDR) solution. As part of the rollout, they configure the EDR agents to monitor all process executions, file system changes, and network connections on workstations. Which security monitoring concept is primarily being enhanced by this implementation?

  1. AThreat Hunting
  2. BBehavioral Analysis
  3. CLog Aggregation
  4. DVulnerability Scanning
Show answer & explanation

Correct answer: B. Behavioral Analysis

Monitoring process executions, file system changes, and network connections across endpoints are key inputs for behavioral analysis. EDR solutions use this data to establish a baseline of normal activity and detect deviations that may indicate malicious behavior, rather than just collecting logs, actively hunting, or scanning for known vulnerabilities.

Why the other options are wrong

  • A. Threat Hunting is a proactive search for threats, not the underlying monitoring technology itself.
  • C. Log Aggregation is about collecting logs, but doesn't describe the analysis of that data for anomalies.
  • D. Vulnerability Scanning identifies known weaknesses, not real-time activity monitoring.

Behavioral Analysis

A security monitoring technique that establishes a baseline of normal system or user activity and then identifies deviations or anomalies that may indicate malicious activity.

  • Focuses on patterns and deviations.
  • Uses machine learning and statistical methods.
  • Effective at detecting unknown or zero-day threats.
  • Requires extensive data collection (processes, network, files).

Memory trick: Monitoring is watching, and behavioral analysis watches how things act.

More Security Concepts questions