StudyToCert

All certifications / Security+ / Lessons

CompTIA Security+ SY0-701 · Domain 4: Security operations

EDR/XDR, DLP, UEBA

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Traditional antivirus compares files against signatures of known malware. Modern attacks use fileless techniques, legitimate admin tools and stolen credentials that signatures cannot catch. The newer tools on the Security+ objectives watch behavior instead: what processes do, where data goes and how users normally act. Endpoint detection and response (EDR), extended detection and response (XDR), data loss prevention (DLP) and user and entity behavior analytics (UEBA) each focus on a different question, and exam questions test whether you can match a scenario to the right one.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study Security+ for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Security+ study plan