Security Operations第 79 / 100 题
Which endpoint solution continuously records activity and enables investigation and automated response to threats on hosts?
a.EDR
b.Antivirus signature file
c.Host firewall
d.Screen lock policy
解析
Endpoint detection and response (EDR) continuously monitors endpoint behavior, records telemetry, and supports rapid investigation and automated containment. It goes beyond signature antivirus by detecting suspicious behavior. It is central to modern threat hunting and response.
免费刷完整 100 道题库 — 无需注册。
同考点相关题目
- Which scan identifies known weaknesses in systems without actively exploiting them?
- An authorized simulated attack that attempts to exploit vulnerabilities to test defenses is a:
- Which detection method flags activity that deviates from an established normal pattern?
- Which practice ensures logs cannot be tampered with by centralizing them on a protected, write-once server?
- A discussion-based session where a team walks through their response to a hypothetical incident is called a:
- Which automation approach uses playbooks to coordinate tools and streamline security operations tasks?