ISC2 Certified in Cybersecurity (CC)Network SecurityHard

A system administrator is tasked with securing all endpoints within the organization, including laptops, desktops, and servers. The goal is to detect and respond to advanced threats, such as fileless malware and sophisticated ransomware, beyond what traditional antivirus can handle. Which security solution specifically focuses on comprehensive endpoint protection and response capabilities?

  1. AData Loss Prevention (DLP)
  2. BEndpoint Detection and Response (EDR)
  3. CNetwork Access Control (NAC)
  4. DUnified Threat Management (UTM)
Show answer & explanation

Correct answer: B. Endpoint Detection and Response (EDR)

Endpoint Detection and Response (EDR) solutions go beyond traditional antivirus by continuously monitoring endpoint activity, collecting data, and using advanced analytics to detect and respond to sophisticated threats like fileless malware and ransomware, providing comprehensive endpoint protection.

Why the other options are wrong

  • A. DLP prevents sensitive data from leaving the organization but isn't primarily focused on detecting and responding to advanced malware on endpoints.
  • C. NAC controls who can access the network and what they can do, but doesn't focus on advanced threat detection on the endpoint itself.
  • D. UTM is an all-in-one security appliance for network perimeter, not specifically focused on advanced endpoint threat detection and response.

Endpoint Detection and Response (EDR)

An integrated endpoint security solution that continuously monitors and collects data from endpoint devices, using advanced analytics to detect, investigate, and respond to cyber threats.

  • Monitors endpoint activity in real-time.
  • Detects advanced threats (fileless, ransomware).
  • Provides forensic data for investigation.
  • Enables automated or manual response actions.

Memory trick: EDR is like a 'CSI team' for every computer, constantly watching, investigating, and stopping advanced threats.

More Network Security questions