100-160 Question 107
Select 3A cybersecurity technician is tasked with securing an organization's endpoints against malware and unauthorized access. They decide to implement endpoint security measures using Endpoint Detection and Response (EDR) solutions. Which of the following features are typically provided by EDR solutions?
- A
Real-time monitoring and analysis of endpoint activity
- B
Encryption of email communications to prevent phishing attacks
- C
Automated response to detected threats, such as isolating an affected endpoint
- D
Periodic patching of operating systems and applications
- E
Threat hunting capabilities to identify advanced persistent threats (APTs)
Show answer and explanation
Correct answers: A, C, E
Explanation
EDR solutions are designed to provide comprehensive endpoint protection by offering features like real-time monitoring, automated threat responses, and advanced capabilities like threat hunting. These features help organizations detect, respond to, and prevent endpoint-level security threats. However, some functions like email encryption and patch management are outside the scope of EDR and require other specific solutions.
- A. Correct.
Real-time monitoring and analysis of endpoint activity is a key feature of EDR solutions, allowing for proactive detection and prevention of malicious activities.
- B. Incorrect.
Encryption of email communications is typically handled by email security solutions, not EDR. While it is a good security practice, it is not specific to EDR capabilities.
- C. Correct.
Automated response to detected threats is a core function of EDR systems, enabling rapid containment and mitigation of potential security incidents.
- D. Incorrect.
Periodic patching of operating systems and applications is typically managed by patch management tools, not EDR solutions.
- E. Correct.
Threat hunting capabilities are an advanced feature of many EDR platforms, allowing security teams to proactively search for and mitigate advanced threats, such as APTs.