Cisco CCNP Security Core (SCOR) 350-701Endpoint Security and Secure Network AccessMedium
A security analyst is investigating a suspected data exfiltration incident from an endpoint. The endpoint is running an Endpoint Detection and Response (EDR) solution. Which EDR capability would be most effective in determining the scope and method of the data exfiltration?
- ABehavioral analytics and forensic data collection
- BAntivirus signature scanning
- CReal-time threat intelligence feeds
- DNetwork firewall rules enforcement
Show answer & explanationAnswer & explanation
Correct answer: A. Behavioral analytics and forensic data collection
Behavioral analytics and forensic data collection are core EDR capabilities that allow for detailed investigation into endpoint activities, identifying anomalous behavior, process execution, file access, and network connections critical for understanding data exfiltration.
Why the other options are wrong
- B. Antivirus signature scanning primarily detects known malware and would not be effective in understanding the method or scope of data exfiltration if the activity is not tied to a known signature.
- C. Real-time threat intelligence feeds provide information on known threats but do not directly offer forensic data or behavioral analysis of a specific endpoint's activity to determine exfiltration details.
- D. Network firewall rules enforcement controls traffic flow but does not provide visibility into endpoint processes, file access, or internal activities related to data exfiltration.
EDR Behavioral Analytics & Forensics
Endpoint Detection and Response (EDR) solutions use behavioral analytics to detect suspicious activities and collect forensic data to investigate security incidents on endpoints.
- Detects anomalous process execution, file access, network connections.
- Collects detailed logs and artifacts for incident investigation.
- Helps identify root cause, scope, and method of attacks.
- Crucial for advanced threat detection and response.
Memory trick: EDR 'Detects, Dissects, and Documents' endpoint threats.