Cisco Certified Support Technician (CCST) CybersecurityEndpoint SecurityHard
A security analyst needs to investigate a potential phishing attack where an employee clicked on a malicious link. They want to understand the exact sequence of events on the endpoint, including process execution, file changes, and network connections made after the click. Which endpoint security capability would be most valuable for this detailed forensic analysis?
- AData Loss Prevention (DLP) alerts
- BHost-based Intrusion Prevention System (HIPS)
- CAntivirus signature database
- DEndpoint Detection and Response (EDR) logging and telemetry
Show answer & explanationAnswer & explanation
Correct answer: D. Endpoint Detection and Response (EDR) logging and telemetry
EDR systems continuously collect and store detailed telemetry data about endpoint activities, including process execution, file system changes, and network connections. This rich dataset is invaluable for reconstructing the sequence of events during a forensic investigation of a compromise.
Why the other options are wrong
- A. DLP alerts focus on data exfiltration, not the full chain of events of an initial compromise.
- B. HIPS prevents malicious actions but doesn't offer the comprehensive logging needed for forensic analysis of past events.
- C. Antivirus signatures detect known threats but don't provide a detailed event timeline for forensics.
EDR Telemetry and Forensics
The capability of Endpoint Detection and Response (EDR) systems to continuously collect detailed endpoint activity data (telemetry) and provide tools for forensic analysis to reconstruct security incidents.
- Records process activity, file changes, network connections.
- Enables deep dive into incident timelines.
- Crucial for understanding attack vectors and scope.
Memory trick: EDR's logs are the 'CCTV footage' of your endpoint's activities.