Cisco CCNP Security Core (SCOR) 350-701Endpoint Security and Secure Network AccessMedium
A security architect is designing an endpoint security architecture that must protect against fileless malware and ransomware, provide deep visibility into endpoint processes, and offer rapid response capabilities across a hybrid environment. The solution must integrate seamlessly with existing security operations tools. Which modern endpoint security solution best meets these requirements?
- AData Loss Prevention (DLP)
- BEndpoint Detection and Response (EDR)
- CTraditional Signature-Based Antivirus
- DHost-based Intrusion Prevention System (HIPS)
Show answer & explanationAnswer & explanation
Correct answer: B. Endpoint Detection and Response (EDR)
EDR solutions are specifically designed to detect and respond to advanced threats like fileless malware and ransomware by providing deep visibility into endpoint activities, continuous monitoring, and robust response capabilities, making them superior to traditional AV or HIPS for these modern challenges.
Why the other options are wrong
- A. DLP focuses on preventing data exfiltration, not threat detection and response against malware.
- C. Traditional AV relies on signatures and struggles against fileless malware and zero-day threats.
- D. HIPS provides preventive controls but often lacks the deep visibility and comprehensive response features of EDR.
Modern Endpoint Security
Next-generation endpoint protection that goes beyond traditional antivirus to include advanced threat detection, response, and forensic capabilities.
- Protects against fileless malware, ransomware, and zero-day threats.
- Provides deep visibility into endpoint behavior and activities.
- Enables rapid investigation and remediation of incidents.
Memory trick: For modern threats, you need an 'EDR detective' on every endpoint.