220-1102 Question 419
Single answerManaged detection and response (MDR)A small medical billing company has only one IT technician and no overnight staff. After a ransomware attempt, management wants a service that will continuously monitor endpoint and network activity, analyze alerts, and provide human-led response guidance or direct containment when suspicious behavior is detected. The company still wants to keep its existing antivirus product. Which solution best meets these requirements?
- A
Implement managed detection and response (MDR) from a security provider
- B
Replace antivirus with a basic host-based firewall on each workstation
- C
Purchase a standalone SIEM platform and review alerts manually each morning
- D
Deploy full-disk encryption on all laptops and desktops
Show answer and explanation
Correct answer: A
Explanation
The best answer is managed detection and response (MDR) because MDR is designed for organizations that need outsourced security monitoring and incident response support, often on a 24/7 basis. In practical terms, MDR providers typically collect and analyze telemetry from endpoints, networks, cloud services, or logs; investigate suspicious activity; and recommend or perform response actions based on the service agreement. This makes MDR especially useful for smaller organizations that do not have an internal security operations center (SOC). By contrast, a SIEM is primarily a technology platform for log aggregation and correlation and still requires trained staff to monitor and act on alerts unless paired with a managed service. Full-disk encryption and host-based firewalls are important security controls, but they do not provide the managed detection and response capability described in the scenario. This aligns with common security best practices such as layered defense and using managed security services when in-house resources are limited, as reflected in vendor MDR service descriptions and general guidance from NIST on continuous monitoring and incident response functions.
- A. Correct.
Correct. Managed detection and response (MDR) is a service that provides continuous monitoring, threat detection, analysis, and typically human expertise for investigation and response. This matches the scenario because the company lacks 24/7 internal staff and wants a provider to help identify and respond to threats while keeping its current antivirus in place. MDR commonly complements existing security tools rather than requiring them to be removed.
- B. Incorrect.
Incorrect. A host-based firewall can help control inbound and outbound traffic on an endpoint, but it does not provide continuous threat hunting, alert analysis, or expert-led response. Someone might choose this because firewalls are a security control, but they do not meet the requirement for managed monitoring and response.
- C. Incorrect.
Incorrect. A SIEM can centralize and correlate logs, but by itself it is a platform, not a managed service. In this scenario, the company specifically lacks the staff to monitor and investigate alerts overnight. Buying a SIEM without personnel or a managed service would still leave the organization unable to respond quickly to active threats.
- D. Incorrect.
Incorrect. Full-disk encryption protects data at rest if a device is lost or stolen, but it does not detect malicious activity, analyze alerts, or contain attacks in progress. This is a valuable security measure, but it does not solve the company's stated need for continuous monitoring and response.