From the course: ISC2 Certified Information Systems Security Professional (CISSP) (2024) Cert Prep

Unlock this course with a free trial

Join today to access over 23,200 courses taught by industry experts.

Endpoint monitoring

Endpoint monitoring

- [Instructor] We have a tremendous number of diverse computing endpoints throughout our organizations. In addition to the many desktop and laptop computers used by individuals and servers in our data centers in the cloud, we have mobile devices, Internet of Things sensors, and many other network-enabled devices on our networks. These endpoints are often the first target of attackers seeking to penetrate our defenses. They target relatively unprotected endpoints in the hope that they will be able to use that access as the jumping off point for a larger attack. This makes monitoring these endpoints a crucial task for cybersecurity analysts. This monitoring should begin with the basics. Organizations are likely already monitoring processor activity, memory consumption, and file system activity for signs of operational issues. These same metrics can provide important security insight as well. For example, unexplained spikes in processor and memory consumption may indicate that an…

Contents