During an assessment, traditional antivirus produces no alerts, but an Endpoint Detection and Response (EDR) solution flags rapid, sequential file modifications. Which conclusion is MOST accurate regarding the endpoint's status?
Make the call. Every option has a note waiting here.
Notes on all 4 options
- ASignature-based antivirus only catches known patterns, so its silence does not prove the endpoint is clean.
- BCorrect: rapid sequential file modifications are a behavioral sign of ransomware or similar activity that signature-based tools can miss.
- COS telemetry and patching do not typically rewrite large numbers of user files in rapid succession.
- DDismissing the alert as indexing without investigation is risky; background indexing reads files rather than modifying them rapidly.