Soru

Zorluk: KolayEndpoint Detection and Response (EDR)

A security administrator wants to collect continuous host-level telemetry, such as process creation events, registry modifications, and network connections, to detect fileless malware and zero-day threats in real time across corporate workstations. Which of the following security solutions best fulfills this requirement?

  1. Endpoint Detection and Response (EDR)Cevap
  2. B
    Legacy Antivirus (AV)
  3. C
    Next-Generation Firewall (NGFW)
  4. D
    Network Intrusion Detection System (NIDS)

Cevap

Endpoint Detection and Response (EDR)
Endpoint Detection and Response (EDR) provides continuous monitoring and recording of host activity (such as process creation, memory utilization, and system modifications). This telemetry allows security teams to detect behavioral anomalies, fileless malware, and zero-day exploits that bypass signature-based tools.

Adım Adım Çözüm

1
Identify the primary operational requirement.
The goal is to capture continuous host-level telemetry (process lineage, registry changes) to identify zero-day and fileless attacks.
Traditional network-level or signature-based security controls cannot observe local operating system behavioral events.
2
Evaluate the capabilities of host security controls.
Endpoint Detection and Response (EDR) installs an agent directly on endpoints to record real-time telemetry and perform behavioral threat detection.
EDR specifically fills the visibility gap left by legacy antivirus and perimeter network defenses.

Anahtar Kavram

Endpoint Detection and Response (EDR) Telemetry and Behavioral Detection
Bu soruyu puanla