A+ Lesson

Malware Detection and Response Tools for A+

Last updated: 6/10/2026

Short answer

- Antivirus/anti-malware: endpoint agents that scan and block known threats; useful first-line defense. - EDR: behavioral telemetry and response capabilities on endpoints; helps detect stealthy or fileless threats. - MDR: outsourced monitoring and response using vendor analysts; useful when in-house capability is limited. - XDR: correlates telemetry across multiple sources for broader detection. Technicians should know which category an environment uses and when to escalate.

Why it appears on the exam

- Given an alert that shows behavioral evidence (script launching PowerShell to download payload), identify EDR as the appropriate tool to investigate. - From a list, pick MDR as the managed service option and XDR as the cross-domain telemetry solution.

Key concepts

Concept 1

Required terms

Antivirus: Traditional endpoint software that uses signature-based and heuristic techniques to detect and remove known malicious files and behaviors. Anti-malware: A broader term for tools designed to detect and remediate malware, including signature, heuristic, and behavior-based techniques. EDR (Endpoint Detection and Response): Agent-based solutions that monitor endpoint behavior, log telemetry, and enable detection, investigation, and containment of threats on endpoints. MDR (Managed Detection and Response): A service model where a vendor or provider monitors telemetry, performs threat hunting, and responds to incidents on behalf of the organization.

Example

A workstation flagged by AV for a Trojan file -> technician uses quarantine and follows escalation if symptoms persist.

Concept 2

How Malware Detection and Response Tools works

- Antivirus/anti-malware: endpoint agents that scan and block known threats; useful first-line defense. - EDR: behavioral telemetry and response capabilities on endpoints; helps detect stealthy or fileless threats. - MDR: outsourced monitoring and response using vendor analysts; useful when in-house capability is limited. - XDR: correlates telemetry across multiple sources for broader detection. Technicians should know which category an environment uses and when to escalate.

Example

EDR alert shows a script spawning a suspicious child process -> escalate to security team or MDR provider if present.

Concept 3

Common confusion

- Treating MDR as a product rather than a service model. - Expecting antivirus alone to catch fileless or advanced persistence attacks; such cases often need EDR/XDR.

Example

Organization subscribes to MDR -> contact the provider when a confirmed compromise occurs.

Concept 4

Core 2 (220-1202) question cues

Given an alert that shows behavioral evidence (script launching PowerShell to download payload), identify EDR as the appropriate tool to investigate; From a list, pick MDR as the managed service option and XDR as the cross-domain telemetry solution.

Example

A workstation flagged by AV for a Trojan file -> technician uses quarantine and follows escalation if symptoms persist.

Sample questions

Select an answer to reveal the explanation. For tracked practice and weak-area review, use the Cultiv8 app.

Q1.A technician is troubleshooting this situation: A workstation flagged by AV for a Trojan file -> technician uses quarantine and follows escalation if symptoms persist. What should they identify?

Q2.A technician sees this situation: EDR alert shows a script spawning a suspicious child process -> escalate to security team or MDR provider if present. Which answer should they choose?

Q3.Read this A+ scenario: Organization subscribes to MDR -> contact the provider when a confirmed compromise occurs. Which term or action matches it?

Practice this lesson in Cultiv8

The app adds tracked practice, targeted remediation, saved session history, and future readiness scoring.

Continue in Cultiv8