Cisco Certified Support Technician (CCST) CybersecurityEndpoint SecurityMedium
A company is concerned about employees downloading and executing unknown or potentially malicious files from the internet. They want to provide a safe environment for users to open suspicious attachments or browse untrusted websites without risking the integrity of their corporate workstations. Which endpoint security technology would best meet this requirement?
- ASecure Boot
- BApplication Sandbox
- CEndpoint Detection and Response (EDR)
- DFull Disk Encryption (FDE)
Show answer & explanationAnswer & explanation
Correct answer: B. Application Sandbox
An Application Sandbox provides an isolated environment where suspicious files or applications can be executed without affecting the host system. This directly addresses the need to safely open untrusted content.
Why the other options are wrong
- A. Secure Boot ensures the system boots only with trusted software, but doesn't protect against malicious files executed post-boot.
- C. EDR detects and responds to threats but doesn't primarily offer an isolated environment for safe execution of unknown files.
- D. FDE protects data at rest by encrypting the entire disk, which is unrelated to safely executing unknown files.
Application Sandbox
A security mechanism for running programs in an isolated environment, restricting their access to system resources and preventing potential harm to the host system.
- Isolates untrusted code from the host system.
- Prevents malware from spreading or causing damage.
- Often used for analyzing suspicious files or browsing untrusted websites safely.
Memory trick: Think of a sandbox where kids play safely, separated from the rest of the yard.