Endpoint Detection and Response (OBJ 4.5) Flashcards
1
Q
End Point Detection and Response (EDR)
A
Category of security tools that monitor endpoints and network events and record the information in a central database.
This is where -
Analysis , Detection, Investigation Reporting and alerting takes place.
2
Q
File Integrity Monitoring
A
Used to validate the integrity of the operating system and application software files using a verification method between the current file state and a known, good baseline.
3
Q
EDR - 6 step process
A
- Data Collection
- Data Consolidation
- Threat Detection
- Alerts and Threat Response
- Threat Investigation
- Remediation
4
Q
A