Understanding the difference between DLP Endpoint Prevent and Endpoint Discover.
search cancel

Understanding the difference between DLP Endpoint Prevent and Endpoint Discover.

book

Article ID: 256122

calendar_today

Updated On:

Products

Data Loss Prevention Endpoint Discover Data Loss Prevention Endpoint Prevent

Issue/Introduction

Effectively deploying the DLP Agent requires a clear distinction between the capabilities of Endpoint Prevent and Endpoint Discover.

Resolution

The Shared Architecture

Both modules rely on the same underlying infrastructure to keep the environment secure:

  • Endpoint Agents: Software installed directly on computers that holds security policies and detects violations.

  • Endpoint Servers: The middle layer that receives incident reports from the connected agents.

  • Enforce Server: The central management hub that collects all data from the Endpoint Servers.

 

Endpoint Prevent: Stopping Data in Motion

This module acts as a real-time guard, monitoring and blocking confidential data from leaving a user's computer.

  • Real-Time Responses: If a user attempts an unauthorized transfer, the agent can block the action, ask the user to confirm their intent, show a warning pop-up, or trigger custom responses (like forcing USB file encryption).

  • Always-On Protection: The agent enforces security policies even if the computer is entirely disconnected from the network.

  • Secure Offline Logging: If an incident occurs while offline, the data is encrypted and saved to the hard drive. It automatically uploads to the server once the computer reconnects.

The below figure presents an example flow of generating an incident.

 

Endpoint Discover: Finding Data at Rest

This module acts as an internal auditor, scanning endpoint computers for stored confidential data that violates company policy.

  • Targeted Scanning: Administrators can configure scans across thousands of computers, applying specific filters for directories, file sizes, or modification dates.

  • Windows Remediation: If confidential files are found on a Windows PC, the agent can quarantine them or use the FlexResponse API to trigger custom automatic actions (such as engaging a third-party tool to encrypt the files).

  • Mac Remediation: On Mac computers, the agent simply logs an incident when it finds confidential data. FlexResponse and Quarantine options are not available.

  • Uninterrupted Scanning: Scans continue running locally even when the computer is disconnected from the corporate network or the internet.

  • Flexible Controls: Administrators can set strict time limits for scans or configure them to auto-terminate if the server stops receiving scan data for a set period.

 

Additional Information

As Symantec DLP keeps evolving, improvements are added with every new release and it is always good to check the new release documentation for new features.

About Endpoint Discover

About Endpoint Discover Scanning

About Endpoint Prevent Monitoring

Endpoint Prevent monitoring