A SOC analyst recommends adding a layer of defense for all endpoints that will better protect against external threats regardless of the device’s operating system. Which of the following best meets this requirement?
To add a layer of defense for all endpoints, regardless of the device's operating system, the best option is:
D. EDR (Endpoint Detection and Response)
EDR solutions are specifically designed to provide advanced threat detection, investigation, and response capabilities on endpoints. They can monitor and analyze endpoint activity in real-time, detect suspicious behavior or indicators of compromise, and respond to threats autonomously or with human intervention. EDR solutions typically work across various operating systems, making them suitable for protecting endpoints regardless of the device's OS. While options A, B, and C (SIEM, CASB, and SOAR) are valuable security technologies, they may not directly provide endpoint protection capabilities like EDR does.
EDR goes beyond traditional antivirus by detecting and responding to both known and unknown threats, making it an effective layer of defense for all endpoints, regardless of the operating system.
CASB solutions provide a security layer that helps protect endpoints by controlling and securing access to cloud-based services and applications. CASBs are platform-agnostic, meaning they can work across various operating systems and devices, making them suitable for heterogeneous environments.
CASBs offer features like data loss prevention (DLP), threat detection, access control, and visibility into cloud usage. They are designed to enhance security and compliance when accessing cloud services, regardless of the endpoint's operating system, and can help mitigate external threats that may target cloud-based resources.
Correct
EDR solutions are designed to provide advanced threat detection and response capabilities at the endpoint level. They monitor and analyze endpoint activities in real-time, detect suspicious or malicious behavior, and provide the necessary tools to respond to and mitigate threats.
upvoted 3 times
...
This section is not available anymore. Please use the main Exam Page.CS0-003 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Serac
7 months agoglenndexter
1 year agojohnabayot
1 year, 1 month ago[Removed]
1 year, 5 months agoFoeMarc
1 year, 6 months agokmordalv
1 year, 8 months ago