200-201 Question 176
Single answerA company has recently deployed endpoint technologies to improve its security posture. The cybersecurity analyst notices that one of the solutions is actively monitoring files and processes for suspicious behavior and automatically quarantines threats. This solution also provides rollback capabilities to restore files to their original state. What type of endpoint technology is the analyst observing?
- A
Antivirus (AV)
- B
Endpoint Detection and Response (EDR)
- C
Host-based Intrusion Prevention System (HIPS)
- D
Virtual Private Network (VPN)
Show answer and explanation
Correct answer: B
Explanation
The described technology, with its ability to monitor processes for suspicious behavior, quarantine threats, and provide rollback capabilities, aligns with the functionality of Endpoint Detection and Response (EDR). EDR tools are designed for advanced threat detection and mitigation on endpoints, going beyond traditional antivirus solutions.
- A. Incorrect.
Antivirus (AV) typically scans for known malware signatures and does not offer advanced features like behavior analysis or rollback capabilities.
- B. Correct.
Endpoint Detection and Response (EDR) provides advanced monitoring of processes and files, uses behavior-based detection, and often includes features such as threat quarantine and rollback to mitigate potential damage.
- C. Incorrect.
Host-based Intrusion Prevention System (HIPS) focuses on identifying and blocking suspicious activity on a host but does not typically include rollback capabilities for files.
- D. Incorrect.
Virtual Private Network (VPN) is primarily used for securing communication over networks and does not monitor files or processes for suspicious activity.