Endpoint Detection and Response (OBJ 4.5) Flashcards

1
Q

End Point Detection and Response (EDR)

A

Category of security tools that monitor endpoints and network events and record the information in a central database.

This is where -
Analysis , Detection, Investigation Reporting and alerting takes place.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

File Integrity Monitoring

A

Used to validate the integrity of the operating system and application software files using a verification method between the current file state and a known, good baseline.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

EDR - 6 step process

A
  1. Data Collection
  2. Data Consolidation
  3. Threat Detection
  4. Alerts and Threat Response
  5. Threat Investigation
  6. Remediation
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly