CCP CCP Endpoint Security & Data Protection 1 — Questions and Answers
Question 1: What is the primary function of an Endpoint Detection and Response (EDR) solution?
- To filter web traffic at the network perimeter
- To monitor, detect, and respond to threats on individual devices (Correct answer)
- To centrally manage user access credentials
- To encrypt data in transit between endpoints
Correct answer: To monitor, detect, and respond to threats on individual devices
EDR solutions continuously monitor endpoint activities to detect, investigate, and respond to advanced threats in real time.
Question 2: Which technology enforces policies that determine whether a device is allowed to connect to a corporate network?
- Data Loss Prevention (DLP)
- Network Access Control (NAC) (Correct answer)
- Host-based Intrusion Detection System (HIDS)
- Full Disk Encryption (FDE)
Correct answer: Network Access Control (NAC)
Network Access Control (NAC) evaluates device health and identity before granting or denying network access.
Question 3: What threat does Full Disk Encryption (FDE) primarily protect against?
- Malware delivered via email attachments
- Unauthorized data access when a device is physically lost or stolen (Correct answer)
- Network-based intrusion attempts on the device
- Insider threats from authenticated users
Correct answer: Unauthorized data access when a device is physically lost or stolen
FDE renders all data on a device unreadable without proper authentication credentials, protecting it if the device is lost or stolen.
Question 4: A Data Loss Prevention (DLP) solution primarily focuses on:
- Detecting malware signatures on endpoints
- Preventing unauthorized transmission of sensitive data outside the organization (Correct answer)
- Blocking network intrusions at the perimeter firewall
- Monitoring user authentication events
Correct answer: Preventing unauthorized transmission of sensitive data outside the organization
DLP monitors and controls data movements to prevent sensitive information from being exfiltrated or shared without authorization.
Question 5: Which endpoint security technique detects unknown malware by analyzing suspicious behaviors rather than known signatures?
- Signature-based detection
- Blacklisting
- Heuristic and behavioral analysis (Correct answer)
- Cryptographic hash comparison
Correct answer: Heuristic and behavioral analysis
Heuristic and behavioral analysis identifies threats based on suspicious activities, enabling detection of zero-day and novel malware.
Question 6: What distinguishes a Host-based Intrusion Prevention System (HIPS) from a HIDS?
- HIPS monitors network traffic while HIDS monitors host processes
- HIPS actively blocks suspicious activity while HIDS only detects and alerts (Correct answer)
- HIPS operates at the network level while HIDS operates at the host level
- HIPS uses signature detection while HIDS uses behavioral analysis
Correct answer: HIPS actively blocks suspicious activity while HIDS only detects and alerts
HIPS actively prevents suspicious activities from executing on the host, whereas HIDS only detects and generates alerts.
What is the primary function of an Endpoint Detection and Response (EDR) solution?