200-201 Question 177
Single answerA cybersecurity analyst is tasked with securing endpoint devices in a corporate network. Which of the following endpoint technologies can detect and prevent malicious software in real-time while also offering advanced analysis capabilities for suspicious activities?
- A
Antivirus software
- B
Endpoint Detection and Response (EDR)
- C
Host-based Intrusion Detection System (HIDS)
- D
Disk encryption
Show answer and explanation
Correct answer: B
Explanation
Endpoint Detection and Response (EDR) is specifically designed to offer real-time detection, prevention, and response to advanced threats on endpoint devices. Unlike traditional antivirus software or HIDS, EDR includes advanced analysis and automation features that make it a robust solution for securing corporate endpoints.
- A. Incorrect.
Antivirus software focuses on identifying and removing known threats using signature-based detection. While effective for basic malware, it lacks advanced analysis and real-time response capabilities.
- B. Correct.
Endpoint Detection and Response (EDR) provides real-time monitoring, advanced threat detection, and automated responses to suspicious activities on endpoint devices, making it the best choice for this scenario.
- C. Incorrect.
Host-based Intrusion Detection System (HIDS) monitors and alerts on suspicious activities but does not actively prevent threats or provide advanced analysis capabilities.
- D. Incorrect.
Disk encryption secures data at rest by converting it into unreadable code but does not offer real-time malware detection or prevention capabilities.