CAS-005 · Question #477
A company detects suspicious activity associated with inbound connections. Security detection tools are unable to categorize this activity. Which of the following is the best solution to help the comp
The correct answer is A. Implement an interactive honeypot.. An interactive honeypot can actively engage with suspicious inbound connections, capturing detailed attacker behavior and tactics, which helps identify and categorize unknown or ambiguous threats more effectively.
Question
A company detects suspicious activity associated with inbound connections. Security detection tools are unable to categorize this activity. Which of the following is the best solution to help the company overcome this challenge?
Options
- AImplement an interactive honeypot.
- BMap network traffic to known IoCs.
- CMonitor the dark web.
- DImplement UEBA.
How the community answered
(53 responses)- A83% (44)
- B9% (5)
- C2% (1)
- D6% (3)
Explanation
An interactive honeypot can actively engage with suspicious inbound connections, capturing detailed attacker behavior and tactics, which helps identify and categorize unknown or ambiguous threats more effectively.
Community Discussion
No community discussion yet for this question.