What Is a Feature of an Endpoint Detection and Response Solution?

Answer Correct answer: C — An EDR solution rapidly and consistently observes and examines endpoint data to detect and mitigate threats.

What is a feature of an endpoint detection and response solution?

  1. ensuring the security of network devices by choosing which devices are allowed to reach the network
  2. capturing and clarifying data on email, endpoints, and servers to mitigate threats
  3. rapidly and consistently observing and examining data to mitigate threats Correct Answer
  4. preventing attacks by identifying harmful events with machine learning and conduct-based defense

Community Votes

C
50%
D
50%

50% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the SCOR distinction between EDR detection/response and EPP prevention; the trap is selecting D because EDR products can also use machine learning.

EDR solutions focus on continuous endpoint visibility, detection, and response rather than prevention alone. This 350-701 study page establishes why option C is the correct feature of an endpoint detection and response solution, while option D describes EPP-style prevention.

The most common wrong answer is D, since it sounds advanced with machine learning and conduct-based defense, but those are prevention features associated with EPP rather than the core EDR feature asked here.

Community Discussion (5 comments)

madboy2 👍 1 Selected: C
Its Answer C, Answer D is more covered by a EPP
Premium_Pils 👍 1 Selected: D
EDR leverages machine learning capabilities. (AMP, which is Ciscos'EDR. uses the threat intelligence of cisco talos.) "In addition to continuous file analysis, it is important to note that EDR is only as good at detecting files as the threat intelligence that powers it. This intelligence leverages large-scale data, machine learning capabilities, and advanced file analysis to help detect threats." https://www.cisco.com/c/en/us/products/security/endpoint-security/what-is-endpoint-detection-response-edr-medr.html#~edr-capabilities
NullNull88 👍 1 Selected: D
preventing attacks by identifying harmful events with machine learning and conduct-based defense
luismg 👍 1 Selected: C
AMP does not perform machine learning on the device, the answer is C
devildog 👍 2
securitytut says this is D.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option C matches the definition of endpoint detection and response: EDR solutions continuously collect endpoint telemetry, rapidly observe activity, and examine data for signs of compromise so security teams can mitigate threats. Cisco SCOR distinguishes EDR from prevention-centric tools by emphasizing detection, investigation, and response. The wording "rapidly and consistently observing and examining data" captures the continuous monitoring and analysis that is central to EDR. Therefore C is the feature that belongs to an EDR solution.

Why the Other Options Are Wrong

Option A describes network access control (NAC), because it is about choosing which devices may reach the network, not endpoint detection and response. Option B is broader than EDR and sounds like email or security analytics platforms that capture and clarify data across email, endpoints, and servers. Option D emphasizes preventing attacks with machine learning and conduct-based defense, which describes endpoint protection platform (EPP) or next-generation antivirus capabilities. Although EDR products may use machine learning, prevention is not the core feature the question is testing.

Community Comment Notes

The community vote was split 50–50, which reflects how strongly option D's machine-learning and prevention wording appeals to learners. As madboy2 noted, "Answer D is more covered by a EPP," meaning prevention belongs to a different endpoint security category. Premium_Pils argued that "EDR leverages machine learning capabilities," citing Cisco AMP and Talos threat intelligence, but that supports ML as an enabling technology rather than the defining EDR feature. luismg countered that AMP does not perform machine learning on the device and concluded C is correct. As devildog noted, "securitytut says this is D," showing that even third-party explanations can conflict with Cisco's EDR-versus-EPP distinction.

Official Reference

Exam Strategy

Watch the question's verb: EDR means detect and respond, so options built around preventing attacks usually belong to EPP. If two answers both mention monitoring or machine learning, pick the one that matches continuous observation and examination over prevention.

Frequently Asked Questions

Why is option D not the correct EDR feature?

Option D describes preventing attacks with machine learning and conduct-based defense, which aligns with EPP or NGAV prevention. EDR's core feature is detection and response, as option C states.

How can Cisco AMP be EDR if it uses machine learning?

Cisco AMP can use machine learning as an enabling technology, but the question asks for the defining EDR feature. SCOR separates EDR detection/response from EPP prevention controls.

Related Analysis

← Back to 350-701 Study Guide