A security analyst wants to better understand the behavior of users and devices in order to gain visibility into potential malicious activities. The analyst needs a control to detect when actions deviate from a common baseline. Which of the following should the analyst use?
Choose an answer
Tap an option to check your answer.
Correct answer: Endpoint detection and response.
Why this is the answer
Endpoint Detection and Response (EDR) systems are designed to continuously monitor and collect data from endpoints (like workstations and servers) to detect and investigate suspicious activities. EDR establishes a baseline of normal behavior and then flags deviations, making it ideal for gaining visibility into user and device actions and identifying potential malicious activities that stray from the norm. An Intrusion Prevention System (IPS) primarily focuses on blocking known threats based on signatures or behavioral patterns, rather than deep analysis of endpoint behavior over time. A sandbox isolates and executes suspicious code in a controlled environment to observe its behavior, which is a different function than continuous endpoint monitoring. Antivirus software primarily detects and removes known malware based on signatures or heuristics, but lacks the comprehensive behavioral analysis capabilities of an EDR.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed