Question

Difficulty: EasyEndpoint Detection and Response (EDR)

A security administrator is evaluating Endpoint Detection and Response (EDR) software to upgrade workstation security across an enterprise environment. Which of the following capabilities are primary features provided by EDR solutions? (Select TWO.)

  1. Continuous real-time telemetry monitoring of host processes, registry changes, and file activityAnswer
  2. B
    Filtering inbound network traffic at the enterprise perimeter boundary based on IP reputation
  3. Automated host isolation capabilities to contain infected devices from the networkAnswer
  4. D
    Sole reliance on static file hash signatures to identify and block malicious execution

Answer

Endpoint Detection and Response (EDR) solutions primarily provide continuous host-level telemetry monitoring and automated response actions such as host network isolation.
The correct options highlight the core design of EDR: recording real-time host activity (such as process execution and file system modifications) and enabling automated containment actions (such as isolating an infected host from the network) to prevent lateral movement.

Step-by-Step Solution

1
Identify the primary scope of EDR solutions
EDR operates directly on host endpoints (workstations and servers) to provide visibility and response actions.
Understanding where EDR operates differentiates host capabilities from network boundary security controls.
2
Evaluate host telemetry and response features
Continuous monitoring of process execution, registry edits, and file changes alongside automated host isolation represent core EDR functions.
EDR moves beyond traditional static antivirus signatures by offering real-time behavioral monitoring and active threat containment.

Key Concept

Endpoint Detection and Response (EDR) Core Capabilities
Rate this question