exam questions

Exam CS0-003 All Questions

View all questions & answers for the CS0-003 exam

Exam CS0-003 topic 1 question 106 discussion

Actual exam question from CompTIA's CS0-003
Question #: 106
Topic #: 1
[All CS0-003 Questions]

A SOC analyst recommends adding a layer of defense for all endpoints that will better protect against external threats regardless of the device’s operating system. Which of the following best meets this requirement?

  • A. SIEM
  • B. CASB
  • C. SOAR
  • D. EDR
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Serac
7 months ago
Selected Answer: D
If you know the acronyms, EDR is the only one that makes any sense here.
upvoted 4 times
...
glenndexter
1 year ago
Selected Answer: D
To add a layer of defense for all endpoints, regardless of the device's operating system, the best option is: D. EDR (Endpoint Detection and Response) EDR solutions are specifically designed to provide advanced threat detection, investigation, and response capabilities on endpoints. They can monitor and analyze endpoint activity in real-time, detect suspicious behavior or indicators of compromise, and respond to threats autonomously or with human intervention. EDR solutions typically work across various operating systems, making them suitable for protecting endpoints regardless of the device's OS. While options A, B, and C (SIEM, CASB, and SOAR) are valuable security technologies, they may not directly provide endpoint protection capabilities like EDR does.
upvoted 4 times
...
johnabayot
1 year, 1 month ago
Selected Answer: D
EDR goes beyond traditional antivirus by detecting and responding to both known and unknown threats, making it an effective layer of defense for all endpoints, regardless of the operating system.
upvoted 1 times
...
[Removed]
1 year, 5 months ago
Selected Answer: D
D) EDR Endpoint Detection & Response. Question doesn't mention anything about cloud, so CASB (Cloud access security broker) wouldn't be correct.
upvoted 3 times
...
FoeMarc
1 year, 6 months ago
CASB solutions provide a security layer that helps protect endpoints by controlling and securing access to cloud-based services and applications. CASBs are platform-agnostic, meaning they can work across various operating systems and devices, making them suitable for heterogeneous environments. CASBs offer features like data loss prevention (DLP), threat detection, access control, and visibility into cloud usage. They are designed to enhance security and compliance when accessing cloud services, regardless of the endpoint's operating system, and can help mitigate external threats that may target cloud-based resources.
upvoted 2 times
...
kmordalv
1 year, 8 months ago
Selected Answer: D
Correct EDR solutions are designed to provide advanced threat detection and response capabilities at the endpoint level. They monitor and analyze endpoint activities in real-time, detect suspicious or malicious behavior, and provide the necessary tools to respond to and mitigate threats.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago