350-701 · Question #739
What is a difference between an EPP solution and an EDR solution?
The correct answer is D. EPP contains a security incident at the network traffic level, and EDR contains a security incident. EPP (Endpoint Protection Platform) focuses on preventing threats before they execute, whereas EDR (Endpoint Detection and Response) provides advanced capabilities for continuous monitoring, detection, investigation, and response to ongoing threats.
Question
What is a difference between an EPP solution and an EDR solution?
Options
- AEPP detects malicious activity on endpoints, and EDR only detects file-based malware on
- BEDR provides endpoint data loss prevention, and EPP remediates hosts to a preinfection state.
- CEDR focuses on detecting network-level threats, and EPP focuses on detecting host-level threats.
- DEPP contains a security incident at the network traffic level, and EDR contains a security incident
How the community answered
(25 responses)- A4% (1)
- C4% (1)
- D92% (23)
Why each option
EPP (Endpoint Protection Platform) focuses on preventing threats before they execute, whereas EDR (Endpoint Detection and Response) provides advanced capabilities for continuous monitoring, detection, investigation, and response to ongoing threats.
EDR solutions provide broader threat detection than just file-based malware; they monitor behavior, processes, and network connections to identify advanced threats, which is a key difference from basic EPP.
While some EDR solutions may incorporate DLP, it is not a universal defining feature. EPP focuses on prevention, and 'remediates hosts to a preinfection state' is more aligned with advanced EDR or incident response capabilities, not EPP's primary function.
Both EDR and EPP primarily focus on endpoint (host-level) threats. EDR provides deeper visibility and forensic capabilities for these host-level threats, but it does not primarily focus on network-level threats over host-level ones.
EPP solutions primarily aim to prevent security incidents from occurring through proactive measures like antivirus, anti-malware, and firewall functionalities, often containing threats at the initial point of entry or execution. EDR solutions, however, continuously monitor endpoint activity to detect sophisticated threats that bypass initial prevention, providing tools for security teams to investigate, contain, and remediate active security incidents.
Concept tested: EPP vs. EDR functionalities
Source: https://www.cisco.com/c/en/us/products/security/what-is-edr.html
Topics
Community Discussion
No community discussion yet for this question.