Endpoint security

Host-based controls on the device itself, such as hardening, a host firewall, anti-malware, host intrusion detection and endpoint detection and response, complementing network controls.

Endpoint security is the set of controls that run on the device itself rather than on the network around it: laptops, desktops, servers, phones and other hosts. Examples include hardening the configuration, a host-based firewall, anti-malware, host-based intrusion detection or prevention, and endpoint detection and response (EDR) as a generic class. Disk encryption and application allow-listing are commonly counted too. The ISC2 exam outline lists endpoint security under secure network components, with host-based controls as its example.

The key point is that endpoint and network controls cover different failures, so neither makes the other redundant. A segmented network does not stop malware that arrives on a USB drive or inside encrypted traffic that the perimeter cannot inspect. A well-protected host does not stop an attacker who can reach an unmanaged device beside it. That is defence in depth, and it is why zero trust designs weigh the device’s state. Network access control connects the two layers by checking an endpoint’s state before it joins.

Exam relevance: a common trap is the idea that a segmented or firewalled network means the hosts need nothing. A scenario about a device that is off the corporate network, or a threat already past the perimeter, is likely to point to host-based controls rather than another network device.