How to Answer Endpoint Protection and Anti-Malware Questions
Your customer asked: “Do you use endpoint protection or anti-malware?”
The short answer
The reviewer is asking what protects laptops, desktops, servers, or other endpoints from malicious activity. A product license is not proof that every relevant endpoint is enrolled, active, monitored, or configured consistently.
Educational guidance only. This page does not determine what is true about your company and does not create a security, compliance, testing, or certification claim.
What the customer is really asking
Understand the question before you answer it.
Questionnaires use terms such as antivirus, anti-malware, endpoint protection, EDR, or endpoint detection and response. These terms can describe different capabilities, so answer using the technology and coverage your company actually operates.
How to answer accurately
Start with the version that matches reality.
If centrally managed protection is deployed
Describe the relevant device population and product category. If you claim full coverage, verify enrollment rather than relying on purchased license count.
If different device types use different protections
Explain the scope rather than implying one tool covers every endpoint.
If employees use unmanaged personal devices
Do not claim company-managed endpoint protection for those devices unless your controls actually extend to them.
A useful answer structure
Status → scope → current practice → supporting information. Start with the direct answer, narrow it to what you can verify, explain how the practice works, and reference evidence only when that evidence actually exists.
Evidence that may help
These are examples, not requirements and not proof that your company has the practice. Use only evidence that really exists and is appropriate to share.
- Endpoint management or security console
- Device enrollment list
- Security-agent health status
- Endpoint security policy
What not to say
- That buying endpoint-security licenses proves deployment.
- That antivirus and EDR are interchangeable terms if your questionnaire distinguishes them.
- That all devices are protected without an accurate inventory.
How Oredra handles this
Answer it once. Keep the truth behind the answer.
Oredra can store endpoint coverage and exceptions as approved scope, which is safer than reusing an old blanket “yes.”
Inside Oredra, a written policy, stated company practice, implemented control, available evidence, tested control, and independent certification remain distinct. Oredra uses approved information to draft future answers and flags questions that the approved profile cannot support.
Authoritative references
Oredra uses primary guidance where a technical or assurance concept benefits from verification. These references do not determine your company's answer.
Related questionnaire questions
Do employees receive security awareness training?
Answer based on training your workforce actually receives. A security policy, onboarding conversation, or occasional reminder may be useful, but it should not be described as a recurring formal training program unless that is what your company operates.
Do you conduct phishing simulations?
A phishing simulation is a controlled exercise that sends simulated phishing messages to evaluate or reinforce employee behavior. General awareness training and real phishing attempts do not automatically count as simulations.
Do you centrally manage company devices or use MDM?
Mobile device management (MDM) or another endpoint-management platform can enforce settings on enrolled devices, but having the tool is not the same as managing every device. Verify which devices and users are actually in scope.