정답: D
The security tool that monitors devices and records the information in a central database for further analysis is endpoint detection and response (EDR). EDR is a tool that provides continuous monitoring and protection of the endpoints, such as laptops, desktops, or mobile devices, that are connected to a network. EDR collects and analyzes various data from the endpoints, such as processes, files, registry entries, network connections, or user activities, and sends them to a central database for further analysis. EDR uses advanced techniques, such as machine learning, behavioral analysis, or threat intelligence, to detect and respond to the security threats and incidents that affect the endpoints, such as malware, ransomware, or advanced persistent threats. EDR can provide the following capabilities and benefits:
It can provide visibility and insight into the endpoint activities and behaviors, and identify the indicators of compromise or attack.
It can provide prevention and mitigation of the security threats and incidents, and perform actions such as blocking, isolating, or removing the malicious or suspicious entities from the endpoints.
It can provide investigation and remediation of the security threats and incidents, and provide the root cause analysis, impact assessment, or recovery options for the endpoints.
It can provide reporting and alerting of the security threats and incidents, and provide the relevant information and evidence for the security analysts or incident responders.