nerdexam
CompTIA

CAS-005 · Question #389

During an adversarial simulation exercise, an external team was able to gain access to sensitive information and systems without the organization detecting this activity. Which of the following mitiga

The correct answer is D. Utilizing decoy accounts and documents. Utilizing decoy accounts and documents (often referred to as honeytokens) is the best mitigation strategy in this scenario. Decoy accounts and documents are designed to look like legitimate, sensitive data or systems, but they are actually trapping. If an adversary accesses these

Submitted by noor.lb· Mar 6, 2026Security Operations

Question

During an adversarial simulation exercise, an external team was able to gain access to sensitive information and systems without the organization detecting this activity. Which of the following mitigation strategies should the organization use to best resolve the findings?

Options

  • AConfiguring a honeypot for adversary characterization
  • BLeveraging simulators for attackers
  • CSetting up a honey network for attackers
  • DUtilizing decoy accounts and documents

How the community answered

(40 responses)
  • A
    18% (7)
  • B
    10% (4)
  • C
    3% (1)
  • D
    70% (28)

Explanation

Utilizing decoy accounts and documents (often referred to as honeytokens) is the best mitigation strategy in this scenario. Decoy accounts and documents are designed to look like legitimate, sensitive data or systems, but they are actually trapping. If an adversary accesses these decoys, it can trigger alerts and give the organization an early warning of the intrusion. This helps the organization detect unauthorized access more quickly and provides the opportunity to respond before actual damage is done.

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice