Cisco CCNP Security Core (SCOR) 350-701Endpoint Security and Secure Network AccessMedium

A company is implementing a Zero Trust network architecture. As part of this, all endpoint devices, regardless of their location (on-premise or remote), must be continuously monitored for compliance and potential threats. Access to network resources will be granted only after a device's security posture is verified in real-time. Which endpoint security technology is fundamental to achieving this continuous monitoring and real-time posture assessment in a Zero Trust environment?

  1. AFirewall with Stateful Packet Inspection
  2. BEndpoint Detection and Response (EDR)
  3. CTraditional Antivirus Software
  4. DIntrusion Prevention System (IPS)
Show answer & explanation

Correct answer: B. Endpoint Detection and Response (EDR)

Endpoint Detection and Response (EDR) provides continuous real-time monitoring of endpoint activity, detects and investigates threats, and enables rapid response. This capability is fundamental to Zero Trust's 'never trust, always verify' principle, as it allows for continuous posture assessment and verification of endpoint health before granting or maintaining access. Traditional AV is reactive, and firewalls/IPS are network-centric, not endpoint-centric for continuous posture.

Why the other options are wrong

  • A. A firewall with stateful packet inspection operates at the network perimeter or segment boundaries and does not provide endpoint-level continuous monitoring or posture assessment.
  • C. Traditional Antivirus software primarily focuses on signature-based detection of known malware and lacks the continuous monitoring and real-time posture assessment capabilities required by Zero Trust.
  • D. An IPS is a network-based security device that detects and prevents network intrusions, but it does not provide continuous monitoring or real-time posture assessment of individual endpoints.

EDR for Zero Trust

Endpoint Detection and Response (EDR) is a key technology in Zero Trust architectures, providing continuous, real-time monitoring of endpoint activities to assess security posture and detect threats, enabling 'never trust, always verify' for device access.

  • Continuous endpoint monitoring.
  • Real-time threat detection and response.
  • Enables dynamic access decisions in Zero Trust.

Memory trick: For Zero Trust, constantly check the endpoint's pulse, not just its ID card.

More Endpoint Security and Secure Network Access questions