Question

Difficulty: EasyEndpoint Detection and Response (EDR)

An organization is deploying an Endpoint Detection and Response (EDR) agent across all enterprise hosts. Which of the following core capabilities differentiate EDR solutions from traditional signature-based antivirus software? (Select TWO.)

  1. Continuous real-time collection and analysis of endpoint behavioral telemetryAnswer
  2. Remote network isolation of compromised hosts while preserving management accessAnswer
  3. C
    Inline network packet filtering based strictly on IP reputation lists
  4. D
    Reliance on perimeter security boundaries to implicitly trust internal host actions

Answer

The features that distinguish EDR solutions from legacy antivirus are continuous real-time collection of endpoint behavioral telemetry and remote network isolation of compromised hosts.
Endpoint Detection and Response (EDR) solutions extend beyond traditional antivirus by continuously recording host behavioral telemetry (such as process trees, file modifications, and local network connections) and enabling rapid containment actions like network isolation of compromised endpoints.

Step-by-Step Solution

1
Identify key EDR features.
EDR emphasizes continuous host telemetry collection and active containment options such as network isolation.
Legacy antivirus relies primarily on static file signatures, whereas EDR continuously analyzes behavior and provides direct incident response capabilities.
2
Evaluate wrong options.
IP reputation filtering is a network firewall control, and assuming internal host trustworthiness relies on perimeter trust rather than endpoint monitoring.
These distractor options represent perimeter control functions or flawed security assumptions rather than host EDR features.

Key Concept

Endpoint Detection and Response (EDR) Core Functions
Estimated Time:1m 0s
Rate this question