A security auditor is reviewing an organization's endpoint security posture. The auditor identifies that while traditional antivirus is deployed, there is no mechanism to detect advanced persistent threats (APTs) that bypass signature-based detection or to provide visibility into endpoint activities post-compromise. The organization needs a solution that can identify stealthy attacks, provide deep forensic capabilities, and enable rapid containment. Which endpoint security technology should the auditor recommend?
- AEndpoint Detection and Response (EDR)
- BData Loss Prevention (DLP)
- CSecurity Information and Event Management (SIEM)
- DNetwork Intrusion Detection System (NIDS)
Show answer & explanationAnswer & explanation
Correct answer: A. Endpoint Detection and Response (EDR)
Endpoint Detection and Response (EDR) systems are designed to continuously monitor endpoint activities, collect detailed data, detect advanced threats (including APTs that bypass traditional AV), provide deep forensic capabilities, and enable rapid response actions like isolating compromised devices. NIDS is network-centric, SIEM aggregates logs, and DLP prevents data exfiltration, none of which provide the necessary endpoint visibility and response for APTs.
Why the other options are wrong
- B. DLP focuses on preventing sensitive data from leaving the organization's control, which is a different security objective than detecting APTs and providing post-compromise forensics.
- C. SIEM aggregates security logs and events from various sources for correlation and analysis, but it relies on other systems for endpoint data collection and does not provide native deep forensic or rapid containment capabilities on the endpoint.
- D. NIDS monitors network traffic for suspicious patterns but lacks endpoint visibility and forensic capabilities to detect stealthy attacks or provide post-compromise analysis on the endpoint itself.
EDR for APT Detection & Forensics
Endpoint Detection and Response (EDR) is an endpoint security solution that continuously monitors endpoints to detect advanced persistent threats (APTs) and stealthy attacks, providing deep forensic visibility and enabling rapid incident response.
- Detects threats beyond signature-based AV.
- Provides deep endpoint visibility and forensic data.
- Enables rapid containment and response to advanced attacks.
Memory trick: To catch hidden threats, you need an endpoint detective with a microscope, not just a guard at the gate.