CAS-005 · Question #389
During an adversarial simulation exercise, an external team was able to gain access to sensitive information and systems without the organization detecting this activity. Which of the following mitiga
The correct answer is D. Utilizing decoy accounts and documents. Utilizing decoy accounts and documents (often referred to as honeytokens) is the best mitigation strategy in this scenario. Decoy accounts and documents are designed to look like legitimate, sensitive data or systems, but they are actually trapping. If an adversary accesses these
Question
During an adversarial simulation exercise, an external team was able to gain access to sensitive information and systems without the organization detecting this activity. Which of the following mitigation strategies should the organization use to best resolve the findings?
Options
- AConfiguring a honeypot for adversary characterization
- BLeveraging simulators for attackers
- CSetting up a honey network for attackers
- DUtilizing decoy accounts and documents
How the community answered
(40 responses)- A18% (7)
- B10% (4)
- C3% (1)
- D70% (28)
Explanation
Utilizing decoy accounts and documents (often referred to as honeytokens) is the best mitigation strategy in this scenario. Decoy accounts and documents are designed to look like legitimate, sensitive data or systems, but they are actually trapping. If an adversary accesses these decoys, it can trigger alerts and give the organization an early warning of the intrusion. This helps the organization detect unauthorized access more quickly and provides the opportunity to respond before actual damage is done.
Community Discussion
No community discussion yet for this question.