Soru

Zorluk: KolayEndpoint Detection and Response (EDR)

An enterprise security team needs to deploy a security capability to corporate laptops that provides continuous behavioral telemetry, process execution monitoring, and the ability to perform remote network host isolation during an incident. Which of the following technologies best meets these operational requirements?

  1. Endpoint Detection and Response (EDR)Cevap
  2. B
    Perimeter Next-Generation Firewall (NGFW)
  3. C
    Network-based Intrusion Detection System (NIDS)
  4. D
    Data Loss Prevention (DLP) solution

Cevap

Endpoint Detection and Response (EDR)
Endpoint Detection and Response (EDR) agents run directly on end-user devices to log process execution, track host behavior in real time, and allow SOC analysts to isolate compromised hosts from the network remotely.

Adım Adım Çözüm

1
Identify the required capabilities from the scenario
The requirements are continuous host-level telemetry, process execution tracking, and remote host containment/isolation capabilities.
Security controls must match the specific functional scope requested by the incident response team.
2
Compare candidate security tools against host-level vs network-level functionality
Only host-based agent tools operating on the endpoint can monitor granular system process behavior and enforce host network interface isolation.
Network appliances like firewalls and NIDS lack visibility into internal OS process execution and file access.
3
Select the host security technology designed for behavioral monitoring and containment
Endpoint Detection and Response (EDR) provides behavioral detection, logging, and remote host isolation capabilities.
EDR agents are engineered specifically to provide real-time endpoint visibility and incident remediation capabilities.

Anahtar Kavram

Endpoint Detection and Response (EDR) capabilities including continuous monitoring and host isolation
Bu soruyu puanla