Endpoint protection fundamentals: antivirus, EDR and safe policy management
Vendor-neutral foundations for whoever runs an endpoint security product: what antivirus (EPP), EDR, MDR and XDR each add, proving every device has a healthy agent, changing policies safely in rings, governing exclusions, protecting the agent from tampering and removal, handing detections to the right people, and offboarding retired devices.
- Level
- Intermediate
- Length
- About 45 minutes
- Contents
- 3 lessons · 1 video · final exam
- Status
- Published · updated 2 Oct 2026
Skills you'll practise
- Distinguish endpoint protection (antivirus), EDR, MDR and XDR by what each adds
- Reconcile an asset list with the security console and identify unprotected, stale and retired devices
- Plan a policy change that starts in a pilot ring, is reviewed and widened, with a rollback plan
- Evaluate an exclusion request and approve only a narrow, owned and reviewed exclusion
- Explain why tamper and uninstall protection matter and how to make approved maintenance changes
- Hand off a detection with the evidence a responder needs, within the limits of your playbook
Course outline
- 1.Endpoint protection fundamentalsVideo · 2 min
- 2.What the layers do, and proving coverageLesson · 15 min
- 3.Policies, rings and exclusionsLesson · 15 min
- 4.Tamper protection, handoff and offboardingLesson · 15 min
- 5.Endpoint protection fundamentals: antivirus, EDR and safe policy management: knowledge checkKnowledge check · 16 questions
- 6.Final exam11 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.