Skip to content

Endpoint protection fundamentals: antivirus, EDR and safe policy management

Vendor-neutral foundations for whoever runs an endpoint security product: what antivirus (EPP), EDR, MDR and XDR each add, proving every device has a healthy agent, changing policies safely in rings, governing exclusions, protecting the agent from tampering and removal, handing detections to the right people, and offboarding retired devices.

Level
Intermediate
Length
About 45 minutes
Contents
3 lessons · 1 video · final exam
Status
Published · updated 2 Oct 2026

Skills you'll practise

  • Distinguish endpoint protection (antivirus), EDR, MDR and XDR by what each adds
  • Reconcile an asset list with the security console and identify unprotected, stale and retired devices
  • Plan a policy change that starts in a pilot ring, is reviewed and widened, with a rollback plan
  • Evaluate an exclusion request and approve only a narrow, owned and reviewed exclusion
  • Explain why tamper and uninstall protection matter and how to make approved maintenance changes
  • Hand off a detection with the evidence a responder needs, within the limits of your playbook

Course outline

  1. 1.Endpoint protection fundamentalsVideo · 2 min
  2. 2.What the layers do, and proving coverageLesson · 15 min
  3. 3.Policies, rings and exclusionsLesson · 15 min
  4. 4.Tamper protection, handoff and offboardingLesson · 15 min
  5. 5.Endpoint protection fundamentals: antivirus, EDR and safe policy management: knowledge checkKnowledge check · 16 questions
  6. 6.Final exam11 questions · passing it completes the course, so people who already know the material can test out

Sources it draws on

The lessons and questions are written from these references, so learners can go back to the original.

See it with your own jobs and topics

Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.