🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 3 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

An organization runs a mix of Windows and Linux application servers in its data center, along with several hundred employee laptops. Leadership is concerned about increasingly sophisticated fileless malware that bypasses traditional signature-based antivirus. Security needs include: 1) real-time behavioral detection on each host, 2) automatic isolation of compromised processes, and 3) centralized telemetry for incident investigations via the SIEM. Which countermeasure best satisfies these requirements?

  • Install a network-based intrusion detection system (NIDS) with full packet capture at the data center perimeter.

  • Implement a secure web gateway with URL filtering and cloud sandboxing.

  • Deploy an endpoint detection and response (EDR) platform to all servers and laptops.

  • Upgrade existing antivirus to the latest signature-based engine and increase update frequency.

ISC2 Systems Security Certified Practitioner (SSCP)
Systems and Application Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot