Soru

Zorluk: OrtaEndpoint Detection and Response (EDR)

During an incident investigation on a Linux developer workstation, a security analyst discovers that an attacker is running fileless malware directly within volatile memory using native utility process injection. Legacy antivirus software failed to trigger an alert because no file was written to the disk drive. Which of the following core capabilities of an Endpoint Detection and Response (EDR) platform allows it to detect and respond to this attack?

  1. Continuous behavioral telemetry monitoring and process execution trackingCevap
  2. B
    Deploying updated static file signature definitions to disk scanners
  3. C
    Applying ingress network filtering rules at the perimeter firewall
  4. D
    Enforcing deep packet inspection on encrypted network transport streams

Cevap

Continuous behavioral telemetry monitoring and process execution tracking
Continuous behavioral telemetry monitoring and process execution tracking is correct because EDR agents record real-time system events, process relationships, and volatile memory activity. This allows the system to identify anomalies such as process injection and fileless execution even when no malicious file resides on local storage.

Adım Adım Çözüm

1
Analyze the attack vector described in the scenario
Identified fileless malware executing directly in volatile memory via process injection without dropping files to disk.
Understanding that legacy antivirus relies on static file signatures explains why traditional disk scanning failed.
2
Evaluate EDR capabilities against memory-resident threats
EDR records real-time host telemetry, monitoring process creation, API system calls, and memory anomalies.
Behavioral detection isolates abnormal process interactions even when no malicious file is present on the storage drive.
3
Select the appropriate security control
Continuous behavioral monitoring is the primary mechanism within EDR for detecting fileless execution.
Host-based behavioral analysis addresses endpoint memory execution directly, unlike network controls or static file scanners.

Anahtar Kavram

EDR Behavioral Monitoring vs. Legacy Signature-Based Antivirus
Bu soruyu puanla