Security OperationsQuestion 79 of 100
Which endpoint solution continuously records activity and enables investigation and automated response to threats on hosts?
a.EDR
b.Antivirus signature file
c.Host firewall
d.Screen lock policy
Explanation
Endpoint detection and response (EDR) continuously monitors endpoint behavior, records telemetry, and supports rapid investigation and automated containment. It goes beyond signature antivirus by detecting suspicious behavior. It is central to modern threat hunting and response.
Practice all 100 questions free — no signup required.
Related questions on this topic
- Which scan identifies known weaknesses in systems without actively exploiting them?
- An authorized simulated attack that attempts to exploit vulnerabilities to test defenses is a:
- Which detection method flags activity that deviates from an established normal pattern?
- Which practice ensures logs cannot be tampered with by centralizing them on a protected, write-once server?
- A discussion-based session where a team walks through their response to a hypothetical incident is called a:
- Which automation approach uses playbooks to coordinate tools and streamline security operations tasks?
Last reviewed: · editorial process
PrepPass Editorial Team · Verified against CompTIA Security+ (SY0-701) · How we review