How Does EDR Protect Endpoints from Malware and Lateral Movement?

Which of the following is used to protect a computer from viruses, malware, and Trojans being installed and moving laterally across the network?

  1. IDS
  2. ACL
  3. EDR Source Reference Answer
  4. NAC

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests your understanding of modern endpoint security tools versus traditional network controls, with the common trap being confusion between network-level monitoring (IDS) and endpoint-specific response capabilities (EDR).

Endpoint Detection and Response (EDR) solutions provide advanced monitoring and automated threat mitigation to prevent malware installation and lateral movement across networks. Community consensus strongly confirms EDR as the definitive answer for endpoint-focused threat containment.

Candidates often select IDS because it detects malicious traffic, but IDS only monitors and alerts without actively protecting endpoints or blocking lateral movement at the host level.

Community Discussion (3 comments)

Syl0 👍 1
IDS - Intrusion Detection System ACL - Access Control List EDR - Endpoint Detection and Response NAC - Network Access Control
baronvon 👍 2 Selected: C
C. EDR (Endpoint Detection and Response) is used to protect a computer from viruses, malware, and Trojans being installed and moving laterally across the network. EDR solutions provide advanced threat detection, response, and mitigation capabilities for endpoints. They monitor endpoint activities for signs of malicious behavior, provide visibility into threats, and can respond to and contain security incidents.
Muhammad_Umair 👍 4
Endpoint Detection and Response (EDR) is an integrated, layered approach to endpoint protection that combines real-time continuous monitoring and endpoint data analytics with rule-based automated response. D

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

EDR platforms continuously monitor endpoint activities using behavioral analytics and telemetry to detect known and unknown threats like viruses, malware, and Trojans. When malicious activity is identified, EDR can automatically isolate the compromised device, halt processes, and prevent the threat from spreading laterally across the network. This proactive, host-based approach directly addresses the scenario described in the question. As noted by the community, EDR combines real-time monitoring with automated response capabilities specifically designed for endpoint protection [Comment 1, 2].

Why the Other Options Are Wrong

An Intrusion Detection System (IDS) operates at the network perimeter or segment level, focusing on traffic analysis rather than host-level execution or containment [Comment 3]. Access Control Lists (ACLs) filter network traffic based on IP and port rules but cannot inspect file payloads or stop malware already running on a device. Network Access Control (NAC) enforces compliance policies before granting network connectivity but lacks the continuous runtime monitoring and threat response features required to contain active infections and lateral movement.

Community Comment Notes

Test-takers consistently validate EDR as the correct choice, emphasizing its layered defense model that merges endpoint data analytics with rule-based automation [Comment 1]. Several users provided helpful acronym breakdowns to distinguish between similar security controls, which simplifies exam-day decision-making [Comment 3]. The unanimous voting distribution reflects strong alignment with official CompTIA objectives regarding modern endpoint threat management.

Official Reference

Exam Strategy

Focus on distinguishing between detection-only tools and those with automated response capabilities. When a question emphasizes stopping malware execution and containing spread at the host level, prioritize EDR over network-centric controls like IDS or NAC.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide