A CISA is reviewing an organization's network security architecture. The organization operates a highly distributed environment with numerous remote offices and mobile users, all requiring secure access to internal resources. Which security control is MOST crucial for protecting against unauthorized access originating from these diverse endpoints?
- AImplementing a robust Intrusion Prevention System (IPS) at the network perimeter.
- BUtilizing a Web Application Firewall (WAF) to protect critical web services.
- CEnforcing strict network segmentation using Virtual Local Area Networks (VLANs).
- DDeploying a comprehensive endpoint detection and response (EDR) solution.
Show answer & explanationAnswer & explanation
Correct answer: D. Deploying a comprehensive endpoint detection and response (EDR) solution.
Given a highly distributed environment with remote offices and mobile users, the attack surface extends significantly beyond the traditional network perimeter to individual endpoints. An EDR solution provides continuous monitoring, threat detection, and response capabilities directly on these endpoints, making it the most crucial control for protecting against unauthorized access originating from these diverse and often less controlled locations.
Why the other options are wrong
- A. IPS is effective at the perimeter but less so for threats originating from already compromised or remote endpoints.
- B. WAF protects web applications, which is important but does not cover the broader endpoint security needs for distributed users.
- C. Network segmentation helps contain threats but doesn't prevent initial unauthorized access originating from vulnerable endpoints.
Endpoint Detection and Response (EDR)
A cybersecurity solution that continuously monitors and collects data from endpoint devices (e.g., laptops, servers), detecting and investigating suspicious activities, and enabling rapid response to threats.
- Provides deep visibility into endpoint activities.
- Crucial for distributed and remote workforces.
- Enables rapid threat containment and remediation.
Memory trick: Each device is a mini-fort, and EDR is its vigilant guard.