Cisco CCNP Security Core (SCOR) 350-701Endpoint Security and Secure Network AccessMedium
A security analyst is investigating a suspected malware infection on an endpoint that bypassed traditional antivirus solutions. The malware exhibits advanced persistent threat (APT) characteristics, including fileless execution and lateral movement attempts. Which endpoint security technology is best suited to detect and respond to such sophisticated threats by continuously monitoring endpoint activity and providing deep visibility for forensic analysis?
- AHost-based Intrusion Prevention System (HIPS)
- BTraditional Antivirus (AV)
- CData Loss Prevention (DLP)
- DEndpoint Detection and Response (EDR)
Show answer & explanationAnswer & explanation
Correct answer: D. Endpoint Detection and Response (EDR)
Endpoint Detection and Response (EDR) solutions are designed to continuously monitor endpoint activity, collect and analyze telemetry data, and provide advanced capabilities for detecting sophisticated threats like APTs and fileless malware. EDR also offers deep visibility and forensic tools crucial for incident response.
Why the other options are wrong
- A. HIPS focuses on preventing malicious actions, but often lacks the deep visibility and forensic capabilities of EDR for post-breach analysis.
- B. Traditional AV primarily relies on signature-based detection and is often ineffective against fileless or zero-day malware.
- C. DLP focuses on preventing data exfiltration, not detecting advanced malware infections or providing forensic analysis.
Endpoint Detection and Response (EDR)
An endpoint security solution that continuously monitors endpoints for suspicious activity, collects data, and provides tools for threat detection, investigation, and response.
- Detects advanced threats (APTs, fileless malware).
- Provides deep visibility and forensic data.
- Enables rapid incident response.
Memory trick: EDR is the 'Eye' that 'Detects' and 'Responds' to every suspicious move on your 'Endpoint'.