nerdexam
CompTIA

SY0-301 · Question #272

A security administrator wants to get a real time look at what attackers are doing in the wild, hoping to lower the risk of zero-day attacks. Which of the following should be used to accomplish this…

The correct answer is B. Honeynets. A honeynet is a network of intentionally vulnerable honeypot systems designed to lure and observe real attackers. Because real threat actors interact with it, a honeynet provides live, real-world intelligence on current attack techniques, tools, and zero-day exploits as they…

Security operations

Question

A security administrator wants to get a real time look at what attackers are doing in the wild, hoping to lower the risk of zero-day attacks. Which of the following should be used to accomplish this goal?

Options

  • APenetration testing
  • BHoneynets
  • CVulnerability scanning
  • DBaseline reporting

How the community answered

(14 responses)
  • B
    93% (13)
  • C
    7% (1)

Explanation

A honeynet is a network of intentionally vulnerable honeypot systems designed to lure and observe real attackers. Because real threat actors interact with it, a honeynet provides live, real-world intelligence on current attack techniques, tools, and zero-day exploits as they are used in the wild. Penetration testing is a scheduled, controlled activity that tests your own defenses rather than observing live attackers. Vulnerability scanning identifies known weaknesses in your environment. Baseline reporting measures deviations from a known-good state. None of these provide real-time visibility into active attacker behavior the way a honeynet does.

Topics

#honeynets#threat intelligence#zero-day#deception technology

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice