ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 224 - SY0-601 discussion

Report
Export

The findings in a consultant's report indicate the most critical risk to the security posture from an incident response perspective is a lack of workstation and server investigation capabilities. Which of the following should be implemented to remediate this risk?

A.
HIDS
Answers
A.
HIDS
B.
FDE
Answers
B.
FDE
C.
NGFW
Answers
C.
NGFW
D.
EDR
Answers
D.
EDR
Suggested answer: D

Explanation:

EDR solutions are designed to detect and respond to malicious activity on workstations and servers, and they provide a detailed analysis of the incident, allowing organizations to quickly remediate the threat. According to the CompTIA Security+ SY0-601 Official Text Book, EDR solutions can be used to detect malicious activity on endpoints, investigate the incident, and contain the threat. EDR solutions can also provide real-time monitoring and alerting for potential security events, as well as detailed forensic analysis for security incidents. Additionally, the text book recommends that organizations also implement a host-based intrusion detection system (HIDS) to alert them to malicious activity on their workstations and servers.

asked 02/10/2024
JP Brune
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first