Cisco CCNP Security Core (SCOR) 350-701Endpoint Security and Secure Network AccessMedium

A security architect is designing an endpoint security architecture that must protect against both known and unknown threats, including zero-day exploits and polymorphic malware. The solution needs to integrate advanced threat detection capabilities with automated response actions. Which combination of endpoint security technologies best addresses this requirement?

  1. ASignature-based Antivirus and Host-based Firewall
  2. BEndpoint Detection and Response (EDR) with Next-Generation Antivirus (NGAV)
  3. CApplication Whitelisting and Network Access Control (NAC)
  4. DData Loss Prevention (DLP) and Traditional Intrusion Prevention System (IPS)
Show answer & explanation

Correct answer: B. Endpoint Detection and Response (EDR) with Next-Generation Antivirus (NGAV)

Next-Generation Antivirus (NGAV) uses machine learning, behavioral analysis, and artificial intelligence to detect both known and unknown (zero-day, polymorphic) threats, going beyond traditional signature-based detection. EDR then provides the continuous monitoring, deep visibility, and automated response capabilities needed for comprehensive protection and remediation against advanced threats.

Why the other options are wrong

  • A. Signature-based AV is ineffective against unknown/zero-day threats; HBF is for traffic filtering.
  • C. Application whitelisting restricts executables but doesn't detect fileless or behavioral threats; NAC controls network access, not endpoint threat detection/response.
  • D. DLP prevents data exfiltration; traditional IPS focuses on network-level intrusions, not endpoint-specific advanced malware.

Modern Endpoint Security

A layered approach typically combining Next-Generation Antivirus (NGAV) for proactive threat prevention and Endpoint Detection and Response (EDR) for continuous monitoring, detection, and response to advanced threats.

  • NGAV uses AI/ML for unknown threat detection.
  • EDR provides visibility, investigation, and response.
  • Together, they offer comprehensive protection against sophisticated attacks.

Memory trick: NGAV is the 'Shield' against new threats, EDR is the 'Detective' for anything that slips past.

More Endpoint Security and Secure Network Access questions