Cisco Certified Support Technician (CCST) CybersecurityEndpoint SecurityMedium
A company is implementing a new endpoint security strategy. They are particularly concerned about advanced persistent threats (APTs) that might bypass traditional antivirus solutions. Which technology offers continuous monitoring, detection, and automated response capabilities specifically tailored for endpoints?
- ANetwork Intrusion Prevention System (NIPS)
- BUnified Threat Management (UTM)
- CSecurity Information and Event Management (SIEM)
- DEndpoint Detection and Response (EDR)
Show answer & explanationAnswer & explanation
Correct answer: D. Endpoint Detection and Response (EDR)
EDR solutions are designed for continuous, real-time monitoring of endpoints, collecting activity data, and providing advanced detection and response capabilities against sophisticated threats like APTs that traditional antivirus might miss.
Why the other options are wrong
- A. NIPS monitors and blocks malicious network traffic, but it operates at the network level, not directly on the endpoint for continuous activity monitoring.
- B. UTM combines multiple security functions (firewall, antivirus, IPS) into a single appliance, but it doesn't offer the deep, continuous endpoint-specific monitoring and response of an EDR.
- C. SIEM aggregates and analyzes logs from various sources, including endpoints, but it's a centralized logging and analysis platform, not an endpoint-specific monitoring and response tool.
Endpoint Detection and Response (EDR)
A cybersecurity solution that continuously monitors and collects data from endpoints, providing advanced threat detection, investigation, and automated response capabilities.
- Offers deep visibility into endpoint activities.
- Designed to combat advanced persistent threats (APTs).
- Enables rapid investigation and remediation.
Memory trick: EDR is like a detective always watching your computer for subtle clues.