A security administrator wants to collect continuous host-level telemetry, such as process creation events, registry modifications, and network connections, to detect fileless malware and zero-day threats in real time across corporate workstations. Which of the following security solutions best fulfills this requirement?
- Endpoint Detection and Response (EDR)Cevap
- BLegacy Antivirus (AV)
- CNext-Generation Firewall (NGFW)
- DNetwork Intrusion Detection System (NIDS)
Cevap
Endpoint Detection and Response (EDR)
Endpoint Detection and Response (EDR) provides continuous monitoring and recording of host activity (such as process creation, memory utilization, and system modifications). This telemetry allows security teams to detect behavioral anomalies, fileless malware, and zero-day exploits that bypass signature-based tools.
Adım Adım Çözüm
Anahtar Kavram
Endpoint Detection and Response (EDR) Telemetry and Behavioral Detection