exam questions

Exam 350-701 All Questions

View all questions & answers for the 350-701 exam

Exam 350-701 topic 1 question 421 discussion

Actual exam question from Cisco's 350-701
Question #: 421
Topic #: 1
[All 350-701 Questions]

What is a characteristic of an EDR solution and not of an EPP solution?

  • A. performs signature-based detection
  • B. decrypts SSL traffic for better visibility
  • C. stops all ransomware attacks
  • D. retrospective analysis
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
IETF1
11 months, 1 week ago
D. retrospective analysis
upvoted 1 times
...
ums008
1 year, 4 months ago
Selected Answer: D
D is correct guys, this website has too many incorrect answers, somebody update them
upvoted 1 times
...
Totosos1
1 year, 7 months ago
Selected Answer: D
I work in an EDR environment, I'm going D here, it's definitely not C!
upvoted 2 times
...
Tuxzinator
1 year, 9 months ago
Selected Answer: D
D is answer
upvoted 3 times
...
Anonymous983475
1 year, 10 months ago
Selected Answer: D
There's no such software that can stop ALL the attacks, so C is the wrong answer. D should be the correct one.
upvoted 2 times
...
Emlia1
1 year, 11 months ago
I prefer D
upvoted 1 times
...
Ed1976
1 year, 11 months ago
Selected Answer: D
It's D
upvoted 2 times
...
smartcarter
2 years ago
Guys Answer is C. https://www.cisco.com/c/en/us/products/security/endpoint-security/what-is-endpoint-detection-response-edr-medr.html
upvoted 1 times
smartcarter
1 year, 12 months ago
Having gone over this question again carefully, I stand by C with another link from cisco. https://www.cisco.com/c/en/us/products/collateral/security/fireamp-endpoints/datasheet-c78-733181.html
upvoted 2 times
Tthurston1
6 months, 2 weeks ago
Also from the same link you've pasted: "Secure Endpoint employs patented technology that automatically uncovers advanced threats that have entered your environment. Powered by continuous monitoring, Secure Endpoint correlates new threat information with your past history and automatically quarantines files the moment they start to exhibit malicious behavior. This automated response to the latest threats provides a faster time to detection and greatly reduces the proliferation of the malware."
upvoted 1 times
Tthurston1
6 months, 2 weeks ago
EPP solutions focuses more on real-time prevention, detection, and response to active threats rather than retrospective analysis - which EDR solutions typically offer.
upvoted 2 times
...
...
...
Tthurston1
6 months, 2 weeks ago
Also from the same link you've pasted: "With continuous file analysis, EDR will be able to flag offending files at the first sign of malicious behavior. If a file is initially deemed safe, but after a few weeks begins to exhibit ransomware activity, EDR will detect the file and start the process of evaluation and analysis, while alerting your organization to act."
upvoted 2 times
Tthurston1
6 months, 2 weeks ago
Answer D
upvoted 2 times
...
...
...
Initial14
2 years, 1 month ago
EPP: blocking known malware at the point of entry using built-in protection mechanisms, including signature-based malware defenses. So A can't be right
upvoted 1 times
...
Initial14
2 years, 1 month ago
EDR focuses primarily on detecting advanced threats, those designed to evade front-line defenses and have successfully entered the environment. An EPP focuses solely on prevention at the perimeter. It is difficult, if not impossible, for an EPP to block 100 percent of threats. A holistic endpoint security solution deploys both EPP and EDR capabilities. If the EDR has retrospective capabilities, this actionable data should be used to automatically remediate systems to their state prior to infection. Id go with D
upvoted 3 times
Initial14
2 years, 1 month ago
EPP: One of the largest threats to an endpoint is malware. Malware can come from many sources, but often it gets onto a device when users click a link from an email or the web. Once inside your environment, malware seeks to infect as much data and as many processes as it can. Ransomware, phishing, and cryptomining are just some of the more recent malware variants
upvoted 2 times
...
Initial14
2 years, 1 month ago
EPP: blocking known malware at the point of entry using built-in protection mechanisms, including signature-based malware defenses. So A can't be right
upvoted 2 times
...
...
arditv
2 years, 1 month ago
Correct answer is D. Without EDR functionality, classic EPP doesn't offer retrospective analysis
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago