nerdexam
CompTIA

CAS-005 · Question #477

A company detects suspicious activity associated with inbound connections. Security detection tools are unable to categorize this activity. Which of the following is the best solution to help the comp

The correct answer is A. Implement an interactive honeypot.. An interactive honeypot can actively engage with suspicious inbound connections, capturing detailed attacker behavior and tactics, which helps identify and categorize unknown or ambiguous threats more effectively.

Submitted by priya_blr· Mar 6, 2026Security Operations

Question

A company detects suspicious activity associated with inbound connections. Security detection tools are unable to categorize this activity. Which of the following is the best solution to help the company overcome this challenge?

Options

  • AImplement an interactive honeypot.
  • BMap network traffic to known IoCs.
  • CMonitor the dark web.
  • DImplement UEBA.

How the community answered

(53 responses)
  • A
    83% (44)
  • B
    9% (5)
  • C
    2% (1)
  • D
    6% (3)

Explanation

An interactive honeypot can actively engage with suspicious inbound connections, capturing detailed attacker behavior and tactics, which helps identify and categorize unknown or ambiguous threats more effectively.

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice