Cisco Certified Support Technician (CCST) CybersecurityEndpoint SecurityHard

A security analyst is reviewing a system that has been compromised. The attacker used a zero-day exploit to gain initial access, bypassing traditional signature-based antivirus. Which endpoint security technology would have been most effective in detecting this type of sophisticated, unknown threat?

  1. AData Loss Prevention (DLP)
  2. BEndpoint Detection and Response (EDR)
  3. CSignature-based Antivirus
  4. DHost-based Firewall
Show answer & explanation

Correct answer: B. Endpoint Detection and Response (EDR)

Endpoint Detection and Response (EDR) systems are designed to monitor endpoint and network events, record behavior, and use advanced analytics (including behavioral and heuristic analysis) to detect and respond to sophisticated, unknown threats like zero-day exploits, which signature-based AV cannot.

Why the other options are wrong

  • A. DLP prevents data exfiltration and is not designed to detect zero-day exploits or initial compromise.
  • C. Signature-based antivirus relies on known threat signatures and would not detect a zero-day exploit.
  • D. A host-based firewall controls network traffic but doesn't detect or respond to exploit execution on the host itself.

Endpoint Detection and Response (EDR)

An integrated, layered endpoint security solution that continuously monitors and collects endpoint data, using advanced analytics to detect, investigate, and respond to threats.

  • Goes beyond traditional antivirus.
  • Focuses on behavioral analysis and anomaly detection.
  • Provides visibility and response capabilities for advanced threats.

Memory trick: EDR is the 'always watching' guard for hidden dangers.

More Endpoint Security questions