コンサルタントのレポートの調査結果は、インシデント対応の観点から見たセキュリティ体制に対する最も重大なリスクは、ワークステーションとサーバーの調査機能の欠如であることを示しています。このリスクを修正するために実装する必要があるのは、次のうちどれですか?
正解:D
Explanation
EDR solutions are designed to detect and respond to malicious activity on workstations and servers, and they provide a detailed analysis of the incident, allowing organizations to quickly remediate the threat. According to the CompTIA Security+ SY0-601 Official Text Book, EDR solutions can be used to detect malicious activity on endpoints, investigate the incident, and contain the threat. EDR solutions can also provide real-time monitoring and alerting for potential security events, as well as detailed forensic analysis for security incidents. Additionally, the text book recommends that organizations also implement a host-based intrusion detection system (HIDS) to alert them to malicious activity on their workstations and servers.