Cisco Certified Support Technician (CCST) CybersecurityIncident HandlingMedium
A security team is analyzing logs from a web server that was recently compromised. They need to identify the initial access vector, the commands executed by the attacker, and any files that were modified or exfiltrated. Which type of incident response tool would be most effective for this task?
- AIntrusion Prevention System (IPS)
- BNetwork Access Control (NAC)
- CEndpoint Detection and Response (EDR)
- DSecurity Information and Event Management (SIEM)
Show answer & explanationAnswer & explanation
Correct answer: C. Endpoint Detection and Response (EDR)
EDR tools specialize in monitoring endpoint activities, including process execution, file system changes, and network connections, making them ideal for detailed forensic analysis of a compromised server to understand attacker actions.
Why the other options are wrong
- A. IPS is for prevention and blocking, not detailed post-compromise analysis.
- B. NAC controls network access, not post-compromise forensic analysis.
- D. SIEM aggregates logs but doesn't provide the deep endpoint visibility needed for this level of detail.
Endpoint Detection and Response (EDR)
A cybersecurity solution that continuously monitors and records endpoint activity, providing visibility into threats and enabling rapid detection and response.
- Collects detailed endpoint telemetry (process, file, network activity).
- Helps detect sophisticated attacks that bypass traditional defenses.
- Facilitates forensic investigation and threat hunting on endpoints.
Memory trick: EDR is like a CCTV camera for your computer, recording everything.