An analyst notices an unpatched web server receiving exploit attempts. The EDR agent generates alerts and captures process behavior, but the host remains unpatched. How should the EDR capability be classified in vulnerability response?
Select an answer to reveal the explanation.
Short Explanation
Think of EDR like a smoke detector on a wall with a hole in it: it tells you fire is starting, but it doesn’t patch the wall. You still need the update to close the hole. The trap is calling detection a fix.
Full Explanation
Endpoint detection and response is primarily a detective capability because it observes host activity, records telemetry, and raises alerts when behavior resembles exploitation. In vulnerability management, that value is risk reduction and response support: it can buy time to patch, guide containment, and confirm whether an attempt succeeded. It does not remove the underlying weakness, because the unpatched software remains vulnerable until a vendor update, configuration change, or compensating control changes the attack surface. A preventive control would aim to stop exploitation before it occurs, such as a WAF rule or application allowlisting, while a corrective control would restore the system after a failure by installing the patch or rebuilding the host. A compensating control would reduce exposure while remediation is pending, for example network segmentation or virtual patching, but the EDR alert itself is not permanent remediation. Exam caveat: CompTIA may ask you to classify the control type rather than the tool name, so focus on what the control does. Operational check: when an EDR alert fires on an unpatched host, verify the patch status, capture evidence, and escalate to the remediation owner.