How Does EDR Protect Endpoints from Malware and Lateral Movement?
Which of the following is used to protect a computer from viruses, malware, and Trojans being installed and moving laterally across the network?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests your understanding of modern endpoint security tools versus traditional network controls, with the common trap being confusion between network-level monitoring (IDS) and endpoint-specific response capabilities (EDR).
Endpoint Detection and Response (EDR) solutions provide advanced monitoring and automated threat mitigation to prevent malware installation and lateral movement across networks. Community consensus strongly confirms EDR as the definitive answer for endpoint-focused threat containment.
Candidates often select IDS because it detects malicious traffic, but IDS only monitors and alerts without actively protecting endpoints or blocking lateral movement at the host level.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
EDR platforms continuously monitor endpoint activities using behavioral analytics and telemetry to detect known and unknown threats like viruses, malware, and Trojans. When malicious activity is identified, EDR can automatically isolate the compromised device, halt processes, and prevent the threat from spreading laterally across the network. This proactive, host-based approach directly addresses the scenario described in the question. As noted by the community, EDR combines real-time monitoring with automated response capabilities specifically designed for endpoint protection [Comment 1, 2].Why the Other Options Are Wrong
An Intrusion Detection System (IDS) operates at the network perimeter or segment level, focusing on traffic analysis rather than host-level execution or containment [Comment 3]. Access Control Lists (ACLs) filter network traffic based on IP and port rules but cannot inspect file payloads or stop malware already running on a device. Network Access Control (NAC) enforces compliance policies before granting network connectivity but lacks the continuous runtime monitoring and threat response features required to contain active infections and lateral movement.Community Comment Notes
Test-takers consistently validate EDR as the correct choice, emphasizing its layered defense model that merges endpoint data analytics with rule-based automation [Comment 1]. Several users provided helpful acronym breakdowns to distinguish between similar security controls, which simplifies exam-day decision-making [Comment 3]. The unanimous voting distribution reflects strong alignment with official CompTIA objectives regarding modern endpoint threat management.Official Reference
Exam Strategy
Focus on distinguishing between detection-only tools and those with automated response capabilities. When a question emphasizes stopping malware execution and containing spread at the host level, prioritize EDR over network-centric controls like IDS or NAC.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →