Following an alert indicating potential ransomware propagation via macro execution on an executive laptop, an incident responder requires immediate containment and detailed investigation tools operating directly on the host. Which TWO of the following capabilities represent primary features of an Endpoint Detection and Response (EDR) solution that address this situation?
- Remotely isolating the host from the network via agent-based controls to halt lateral movement while preserving management connectivity.Cevap
- Recording continuously generated process lineage, file modification, and registry access telemetry for historical analysis.Cevap
- CReconfiguring internal core router access control lists to filter traffic between internal subnets.
- DApplying static hash-based signature updates to scan disk files during scheduled off-peak maintenance windows.
Cevap
The core capabilities of an Endpoint Detection and Response (EDR) platform in this scenario are isolating the host from the network at the software agent layer and recording continuous process, file, and registry telemetry.
Endpoint Detection and Response (EDR) tools emphasize host-level containment and real-time behavioral visibility. Agent-based network isolation immediately stops an active threat from spreading laterally across the enterprise while preserving administrative control. Additionally, EDR provides continuous telemetry recording (such as process trees, memory calls, and file activities) necessary for thorough post-incident analysis.
Adım Adım Çözüm
Anahtar Kavram
Endpoint Detection and Response (EDR) Core Capabilities