問題文
An organization already runs endpoint detection. Why are disk encryption and patch management still listed as endpoint protections?
選択肢
- Because detection products require that the disk be encrypted and that the system be fully patched before their agent will start, so these two measures are prerequisites for the detection layer rather than protections in their own right.
- Because they are the only two controls on the endpoint that can be automated, so they are listed apart from the measures that depend on an analyst reviewing an alert first.
- Because they address exposures that detection does not touch: data read from a lost device, and weaknesses that an attacker can use before any malicious file is involved.
- Because encryption and patching replace the need for detection on endpoints that are kept up to date, so the detection agent can be removed from any machine that is fully patched and encrypted.