Best control for detecting zero-day targeted attacks

Security Incident Management
Answer Correct answer: D — Extended detection and response (XDR) correlates data across multiple security layers.

Which of the following controls would BEST help to detect a targeted attack exploiting a zero-day vulnerability?

  1. Intrusion prevention system (IPS)
  2. Vulnerability scanning
  3. Endpoint detection and response (EDR)
  4. Extended detection and response (XDR) Correct Answer

Community Votes

D
71%
C
29%

71% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the distinction between detection tools, emphasizing that XDR provides the most comprehensive visibility for identifying unknown threats by correlating data across multiple security layers.

Extended Detection and Response (XDR) is the preferred control for detecting zero-day exploits because it correlates behavioral data across endpoints, networks, and clouds, offering broader visibility than endpoint-only solutions.

Choosing Endpoint Detection and Response (EDR) is a common mistake because it effectively detects endpoint anomalies, but XDR is the better answer as it encompasses EDR and correlates data across the entire IT environment.

Community Discussion (4 comments)

sausageman 👍 2 Selected: D
D. Extended detection and response (XDR) XDR includes EDR + SIEM like functionalities
Bl1024 👍 3 Selected: D
XDR has more scop than EDR
isaphiltrick 👍 2 Selected: C
Endpoint Detection and Response (EDR) is designed to detect and respond to suspicious activities on endpoints, which is crucial for identifying targeted attacks that exploit zero-day vulnerabilities. EDR solutions monitor and analyze endpoint activity to identify unusual behavior patterns and potential threats, even if the threat is exploiting an unknown or zero-day vulnerability.
shootnot 👍 2
D- XDR provides a holistic view of environment by detecting incidents based on the logs from multiple sources and provide attack path analysis.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

XDR is the best choice because it integrates data from endpoints, networks, and clouds to detect sophisticated threats. It correlates telemetry across the entire security stack, allowing it to identify the attack paths of zero-day exploits that single-layer tools miss. Community comments confirm XDR provides a "holistic view" and superior scope compared to other options.

Why the Other Options Are Wrong

Vulnerability scanning (B) relies on known signatures and cannot detect zero-days. IPS (A) focuses on prevention at the perimeter and often lacks the behavioral context for unknown threats. While EDR (C) detects endpoint anomalies, it is limited in scope; XDR is superior because it encompasses EDR capabilities plus network and cloud correlation.

Community Comment Notes

Voters overwhelmingly chose D (71%), noting that XDR includes EDR and SIEM functionalities. Commenters emphasized that while EDR is useful, XDR's ability to ingest logs from multiple sources provides the necessary visibility for a targeted attack. One user highlighted that XDR offers more scope than EDR, making it the "best" fit.

Official Reference

Exam Strategy

When asked for the "BEST" control in detection scenarios, look for the solution that offers the broadest visibility and correlation capabilities, such as XDR over EDR.

Related Analysis

Practice All CISM Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISM Practice Test →

← Back to CISM Study Guide