Cisco Certified Support Technician (CCST) CybersecurityEndpoint SecurityEasy

A security analyst is investigating a suspected malware infection on an employee's workstation. The analyst observes unusual network activity originating from the device, including connections to unknown external IP addresses. Which of the following endpoint security technologies would be most effective in actively preventing this type of malicious outbound communication?

  1. AData Loss Prevention (DLP)
  2. BHost-based Firewall
  3. CEndpoint Detection and Response (EDR)
  4. DAntivirus software
Show answer & explanation

Correct answer: B. Host-based Firewall

A host-based firewall operates at the individual endpoint level to control incoming and outgoing network traffic. It can be configured to block unauthorized connections to external IP addresses, thus preventing malicious outbound communication.

Why the other options are wrong

  • A. DLP focuses on preventing sensitive data from leaving the organization, not blocking general malicious outbound connections.
  • C. EDR is for detection and response, offering visibility and remediation, but a firewall is the direct prevention mechanism for network traffic.
  • D. Antivirus primarily detects and removes malware files, but doesn't inherently manage network connections in the same way a firewall does.

Host-based Firewall

A software application that runs on a single host (e.g., a workstation or server) and monitors and controls incoming and outgoing network traffic based on predefined security rules.

  • Protects individual endpoints from network threats.
  • Can filter traffic based on IP addresses, ports, protocols, and applications.
  • Essential for enforcing network security policies at the endpoint level.

Memory trick: The endpoint firewall is like a digital bouncer, checking IDs for all network traffic.

More Endpoint Security questions