Cisco CCNP Security Core (SCOR) 350-701Visibility and EnforcementMedium
A security analyst is investigating a suspected intrusion on the corporate network. They observe unusual outbound connections from several internal hosts to external IP addresses on non-standard ports. The analyst needs to quickly identify the applications generating this traffic and their associated processes. Which security visibility tool is best suited for this task?
- ASecurity Information and Event Management (SIEM) system
- BEndpoint Detection and Response (EDR) solution
- CNetFlow collector
- DIntrusion Prevention System (IPS)
Show answer & explanationAnswer & explanation
Correct answer: B. Endpoint Detection and Response (EDR) solution
An EDR solution provides deep visibility into endpoint activities, including process execution, network connections (source/destination IPs and ports), file changes, and registry modifications. This allows the analyst to directly identify which applications and processes are responsible for the suspicious outbound traffic.
Why the other options are wrong
- A. A SIEM system aggregates logs and alerts from various sources but relies on those sources for data. While it could ingest EDR data, it doesn't provide the direct endpoint process visibility itself.
- C. NetFlow collectors provide flow data (who talked to whom, when, how much) but typically lack the granular process-level visibility needed to identify specific applications generating traffic.
- D. An IPS primarily focuses on preventing known threats and detecting signatures, not providing deep visibility into application-level processes on an endpoint after a potential compromise.
Endpoint Detection and Response (EDR)
A cybersecurity solution that continuously monitors and collects data from endpoint devices (computers, servers) to detect, investigate, and respond to threats.
- Provides deep visibility into endpoint activity (processes, network connections, file system).
- Helps identify and contain advanced threats.
- Focuses on post-breach detection and response.
Memory trick: To catch a cyber-culprit, you need the right tools for the job.