An organization deploys an EDR solution across all endpoints. What critical EDR capability allows the security team to remotely investigate a potentially compromised endpoint without physically touching the machine?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because live response (sometimes called remote shell or live investigation) is a core EDR capability that allows analysts to remotely enumerate processes, pull files, collect memory artifacts, and run commands on an endpoint during active incident response. A is wrong because patch deployment is a patch management function, not a distinctive EDR investigation capability.
Full explanation below image
Full Explanation
B is correct because live response (sometimes called remote shell or live investigation) is a core EDR capability that allows analysts to remotely enumerate processes, pull files, collect memory artifacts, and run commands on an endpoint during active incident response. A is wrong because patch deployment is a patch management function, not a distinctive EDR investigation capability. C is wrong because disk encryption management is a separate security function typically handled by MDM or dedicated encryption tools. D is wrong because software inventory is an asset management function, not an EDR investigation capability.