Cisco CCNP Security Core (SCOR) 350-701Endpoint Security and Secure Network AccessHard

A security auditor is reviewing an organization's endpoint security posture. The auditor notes that while traditional antivirus is deployed, there's a lack of visibility into post-compromise activity, such as lateral movement, privilege escalation, and data exfiltration attempts. The organization needs a solution that can retrospectively analyze endpoint data to identify hidden threats and provide detailed forensic information for incident response. Which technology is specifically designed to address these gaps?

  1. AUnified Threat Management (UTM)
  2. BSecurity Information and Event Management (SIEM)
  3. CEndpoint Detection and Response (EDR)
  4. DNext-Generation Firewall (NGFW)
Show answer & explanation

Correct answer: C. Endpoint Detection and Response (EDR)

Endpoint Detection and Response (EDR) is specifically designed to fill the visibility gap left by traditional antivirus. It continuously monitors endpoint activity, collects telemetry data, and provides capabilities for detecting post-compromise behaviors, threat hunting, and retrospective analysis to uncover hidden threats and support detailed forensic investigations during incident response.

Why the other options are wrong

  • A. UTM is an all-in-one security appliance for small to medium businesses, offering basic firewall, VPN, and AV, not advanced endpoint visibility.
  • B. SIEM aggregates logs from various sources, but EDR provides the rich, granular endpoint telemetry that a SIEM then ingests for correlation.
  • D. NGFW operates at the network perimeter; it doesn't provide deep visibility into endpoint internal activities.

EDR for APT Detection & Forensics

Endpoint Detection and Response (EDR) provides continuous monitoring and deep visibility into endpoint activity, enabling the detection of advanced persistent threats (APTs), post-compromise behaviors, and detailed forensic analysis for incident response.

  • Detects threats that bypass traditional AV.
  • Monitors for lateral movement, privilege escalation.
  • Provides rich data for forensic investigations.

Memory trick: EDR is the 'CCTV camera' and 'forensic lab' for your endpoints, catching what AV misses.

More Endpoint Security and Secure Network Access questions