Endpoint Protection Flashcards

1
Q

Anti-Virus

A

Protects against Trojans, worms, macro viruses.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Anti-malware

A

Protects against broad malicious software category. Stops spyware, ransomware, and fileless malware. Uses signatures to ID threat.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

EDR

A

Endpoint Detection and Response

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Signature

A

Specific pattern of code in code for viruses/malware.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the objectives of EDR?

A

1.Examine what a file is doing.
2. Use ML and process monitoring on device to block based on activity.
3. Can be done with lightweight agent on endpoint
4. Can do root cause analysis and find code used

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How can EDR resolve an identified threat vector?

A
  1. Isolate system from network
  2. Quarantine malicious software into different part of OS.
  3. Roll back config to a known, clean version. Delete malware.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Data Loss Prevention (DLP)

A

Design to prevent sensitive data being sent in the clear or in an encrypted format.

Involves different solutions
1. Firewall-based
2. Cloud-based
3. Client-based

How well did you know this?
1
Not at all
2
3
4
5
Perfectly