nerdexam
Cisco

350-701 · Question #739

What is a difference between an EPP solution and an EDR solution?

The correct answer is D. EPP contains a security incident at the network traffic level, and EDR contains a security incident. EPP (Endpoint Protection Platform) focuses on preventing threats before they execute, whereas EDR (Endpoint Detection and Response) provides advanced capabilities for continuous monitoring, detection, investigation, and response to ongoing threats.

Submitted by sofia.br· Mar 30, 2026

Question

What is a difference between an EPP solution and an EDR solution?

Options

  • AEPP detects malicious activity on endpoints, and EDR only detects file-based malware on
  • BEDR provides endpoint data loss prevention, and EPP remediates hosts to a preinfection state.
  • CEDR focuses on detecting network-level threats, and EPP focuses on detecting host-level threats.
  • DEPP contains a security incident at the network traffic level, and EDR contains a security incident

How the community answered

(25 responses)
  • A
    4% (1)
  • C
    4% (1)
  • D
    92% (23)

Why each option

EPP (Endpoint Protection Platform) focuses on preventing threats before they execute, whereas EDR (Endpoint Detection and Response) provides advanced capabilities for continuous monitoring, detection, investigation, and response to ongoing threats.

AEPP detects malicious activity on endpoints, and EDR only detects file-based malware on

EDR solutions provide broader threat detection than just file-based malware; they monitor behavior, processes, and network connections to identify advanced threats, which is a key difference from basic EPP.

BEDR provides endpoint data loss prevention, and EPP remediates hosts to a preinfection state.

While some EDR solutions may incorporate DLP, it is not a universal defining feature. EPP focuses on prevention, and 'remediates hosts to a preinfection state' is more aligned with advanced EDR or incident response capabilities, not EPP's primary function.

CEDR focuses on detecting network-level threats, and EPP focuses on detecting host-level threats.

Both EDR and EPP primarily focus on endpoint (host-level) threats. EDR provides deeper visibility and forensic capabilities for these host-level threats, but it does not primarily focus on network-level threats over host-level ones.

DEPP contains a security incident at the network traffic level, and EDR contains a security incidentCorrect

EPP solutions primarily aim to prevent security incidents from occurring through proactive measures like antivirus, anti-malware, and firewall functionalities, often containing threats at the initial point of entry or execution. EDR solutions, however, continuously monitor endpoint activity to detect sophisticated threats that bypass initial prevention, providing tools for security teams to investigate, contain, and remediate active security incidents.

Concept tested: EPP vs. EDR functionalities

Source: https://www.cisco.com/c/en/us/products/security/what-is-edr.html

Topics

#EPP#EDR#Endpoint security

Community Discussion

No community discussion yet for this question.

Full 350-701 Practice