100-160 Question 124
Single answerA company's IT security team suspects that a malware infection occurred on an employee's workstation. Which endpoint tool should the team use to gather detailed security assessment information, such as running processes and unusual network connections, to confirm the suspicion?
- A
Antivirus software for routine scans
- B
Endpoint Detection and Response (EDR) tool
- C
Patch management software
- D
Web application firewall (WAF)
Show answer and explanation
Correct answer: B
Explanation
Endpoint Detection and Response (EDR) tools are specifically designed to provide detailed security assessment information by monitoring endpoints in real-time. They can identify suspicious activities, such as unauthorized processes or unusual network traffic, making them the most appropriate tool for investigating potential malware infections on a workstation.
- A. Incorrect.
Antivirus software is useful for detecting known malware during routine scans, but it may not provide detailed information about running processes or unusual network connections in real-time.
- B. Correct.
Endpoint Detection and Response (EDR) tools are designed to collect and analyze endpoint data in real-time, offering detailed insights into suspicious activity such as running processes and unusual network behavior.
- C. Incorrect.
Patch management software is used to ensure systems are up to date with security patches but does not provide detailed security assessment information or identify live threats.
- D. Incorrect.
Web application firewalls (WAFs) are designed to protect web applications from external attacks, but they are not suitable for gathering endpoint security assessment data.