100-160 Question 125
Select 2A company suspects that one of its endpoints has been compromised by malware. As a cybersecurity technician, you are tasked with gathering security assessment information from the endpoint to confirm this suspicion. Which of the following tools would be most appropriate to use in this scenario?
- A
Endpoint Detection and Response (EDR) software
- B
Network Traffic Analyzer
- C
Antivirus or Anti-malware software
- D
Vulnerability Scanner
- E
Packet Sniffer
Show answer and explanation
Correct answers: A, C
Explanation
When assessing a potentially compromised endpoint, tools that specifically target endpoint monitoring and malware detection, such as Endpoint Detection and Response (EDR) and Antivirus/Anti-malware software, are most appropriate. These tools provide detailed insights into endpoint activity and can confirm the presence of malicious software or behavior.
- A. Correct.
Endpoint Detection and Response (EDR) software provides advanced endpoint monitoring and threat detection capabilities, making it highly effective for identifying and assessing potential compromises on an endpoint.
- B. Incorrect.
Network Traffic Analyzer focuses on monitoring and analyzing network traffic, which is not specific to endpoint security assessment. It is more relevant for network-level investigations.
- C. Correct.
Antivirus or Anti-malware software is designed to detect and remove malware on endpoints, making it a suitable tool for confirming a suspected compromise.
- D. Incorrect.
Vulnerability Scanner identifies potential vulnerabilities in systems and applications but does not specifically assess an endpoint for active threats or compromise.
- E. Incorrect.
Packet Sniffer captures and analyzes network packets, which is useful for network-level troubleshooting but not directly applicable to endpoint security assessments.