ISC2 Certified in Cybersecurity (CC)Network SecurityHard

A cybersecurity incident response team is investigating a sophisticated attack where an attacker bypassed traditional perimeter defenses. They suspect that malicious code was executed directly on an endpoint, which then communicated with a command-and-control (C2) server. To detect such advanced threats and provide detailed visibility into endpoint activities, which security solution would be most effective?

  1. ATraditional Antivirus (AV)
  2. BNetwork Intrusion Detection System (NIDS)
  3. CEndpoint Detection and Response (EDR)
  4. DSecurity Information and Event Management (SIEM)
Show answer & explanation

Correct answer: C. Endpoint Detection and Response (EDR)

EDR solutions continuously monitor endpoint activity for advanced threats, provide detailed visibility, and enable rapid response capabilities, which traditional AV and NIDS often lack for sophisticated, endpoint-centric attacks.

Why the other options are wrong

  • A. Traditional AV is primarily signature-based and may not detect sophisticated, fileless, or zero-day attacks that bypass perimeter defenses.
  • B. NIDS monitors network traffic but lacks visibility into internal endpoint processes and activities directly on the device, which is crucial for detecting C2 communication from compromised endpoints.
  • D. SIEM collects and correlates logs from various sources but doesn't provide the deep, real-time endpoint telemetry and response capabilities needed for detailed endpoint investigation.

Endpoint Detection and Response (EDR)

A cybersecurity solution that continuously monitors and collects data from endpoint devices, enabling the detection, investigation, and response to advanced threats.

  • Provides deep visibility into endpoint activities (processes, file changes, network connections).
  • Uses behavioral analytics and machine learning to detect anomalies.
  • Facilitates rapid incident response and threat hunting.

Memory trick: EDR Examines Endpoints, SIEM Scans Systems, NIDS Networks Notice, AV Attacks Avert.

More Network Security questions