Which features does Cisco EDR use for threat detection and response?
Choose an answer
Tap an option to check your answer.
Correct answer: Containment, threat intelligence, and machine learning.
Why this is the answer
Cisco EDR (Endpoint Detection and Response) leverages containment, threat intelligence, and machine learning for comprehensive threat detection and response. Containment isolates compromised endpoints to prevent further spread of threats. Threat intelligence provides real-time data on known threats, vulnerabilities, and attack methods, enabling proactive detection. Machine learning analyzes endpoint behavior to identify anomalous activities indicative of new or evolving threats that might bypass traditional signature-based detection. Firewalling and intrusion prevention are network-centric security features, not core EDR components. Container-based agents refer to a deployment model, not a detection/response mechanism. While EDR solutions often integrate with cloud analysis, and endpoints may have firewall controls, these are not the primary, defining features of EDR's detection and response capabilities.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed