100-160 exam dumps

100-160 practice question 121 of 265

Cisco Certified Support Technician (CCST) Cybersecurity. Associate level, Cisco. Free question with the correct answer and a full explanation.

100-160 Question 121

Select 2

A cybersecurity analyst is tasked with assessing the security status of corporate endpoints. They need to determine whether any unauthorized software is installed and verify that the antivirus definitions are up-to-date. Which of the following tools would be most appropriate for gathering this information?

  1. A

    Endpoint Detection and Response (EDR) software

  2. B

    Network Intrusion Detection System (NIDS)

  3. C

    Patch management software

  4. D

    System inventory and configuration tools

  5. E

    Web Application Firewall (WAF)

Show answer and explanation

Correct answers: A, D

Explanation

To gather security assessment information from endpoints, tools like Endpoint Detection and Response (EDR) and system inventory and configuration tools are ideal. EDR can monitor endpoint activity and ensure antivirus definitions are up-to-date, while system inventory tools can identify installed software and configurations. Tools like NIDS, patch management software, and WAFs serve other purposes and are not suited for this specific task.

  • A. Correct.

    Endpoint Detection and Response (EDR) software is specifically designed to monitor and collect data from endpoints, such as installed software and antivirus definitions, making it suitable for this task.

  • B. Incorrect.

    Network Intrusion Detection System (NIDS) focuses on monitoring network traffic for malicious activity rather than endpoint-specific security assessments, so it is not appropriate here.

  • C. Incorrect.

    Patch management software is used to manage and deploy software updates but does not provide a comprehensive assessment of endpoint security status or software inventory.

  • D. Correct.

    System inventory and configuration tools are useful for gathering endpoint data, such as installed software and system configurations, making them relevant for this scenario.

  • E. Incorrect.

    Web Application Firewall (WAF) protects web applications from attacks but does not provide endpoint security assessment capabilities.

Timed practice exam

Take a 100-160 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam