A security team wants to validate that their EDR solution would detect a common lateral movement technique (pass-the-hash). Which testing methodology is most appropriate?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because purple teaming directly validates EDR detection in the actual environment using real attack techniques, identifies gaps between what should be detected and what is, and produces tuning actions — all without waiting for a real attacker. A is wrong because waiting for a real attack provides no opportunity for controlled measurement or preparation.
Full explanation below image
Full Explanation
B is correct because purple teaming directly validates EDR detection in the actual environment using real attack techniques, identifies gaps between what should be detected and what is, and produces tuning actions — all without waiting for a real attacker. A is wrong because waiting for a real attack provides no opportunity for controlled measurement or preparation. C is wrong because disabling EDR and testing provides no information about detection capability. D is wrong because vendor claims about detection capability do not validate that the specific deployment, configuration, and log pipeline work correctly in the customer's environment.