ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 98 - CS0-003 discussion

Report
Export

A SOC analyst recommends adding a layer of defense for all endpoints that will better protect against external threats regardless of the device's operating system. Which of the following best meets this requirement?

A.
SIEM
Answers
A.
SIEM
B.
CASB
Answers
B.
CASB
C.
SOAR
Answers
C.
SOAR
D.
EDR
Answers
D.
EDR
Suggested answer: D

Explanation:

EDR stands for Endpoint Detection and Response, which is a layer of defense that monitors endpoints for malicious activity and provides automated or manual response capabilities. EDR can protect against external threats regardless of the device's operating system, as it can detect and respond to attacks based on behavioral analysis and threat intelligence. EDR is also one of the tools that CompTIA CySA+ covers in its exam objectives. Official

Reference:

https://www.comptia.org/certifications/cybersecurity-analyst

https://www.comptia.org/blog/the-new-comptia-cybersecurity-analyst-your-questions-answered

https://resources.infosecinstitute.com/certification/cysa-plus-ia-levels/

asked 02/10/2024
Matthew Montgomery
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first