SY0-701 · Question #565
Which of the following would most likely be deployed to obtain and analyze attacker activity and techniques?
The correct answer is C. Honeypot. A honeypot is a deliberately vulnerable decoy system designed to lure attackers, then monitor and record everything they do - making it the ideal tool for studying attacker behavior, tactics, and techniques in a controlled environment. Why the distractors are wrong: A. Firewall…
Question
Which of the following would most likely be deployed to obtain and analyze attacker activity and techniques?
Options
- AFirewall
- BIDS
- CHoneypot
- DLayer 3 switch
How the community answered
(35 responses)- A3% (1)
- B6% (2)
- C89% (31)
- D3% (1)
Explanation
A honeypot is a deliberately vulnerable decoy system designed to lure attackers, then monitor and record everything they do - making it the ideal tool for studying attacker behavior, tactics, and techniques in a controlled environment.
Why the distractors are wrong:
- A. Firewall - blocks or filters traffic based on rules; it prevents attacks but doesn't study them.
- B. IDS (Intrusion Detection System) - detects and alerts on suspicious activity on real systems, but its purpose is protection/alerting, not behavioral analysis of attacker methodology.
- D. Layer 3 switch - a network device that routes traffic between subnets; it has no security monitoring function at all.
Memory tip: Think of a honeypot like a "bait trap" - just as a bear trap uses honey to lure and catch a bear so you can study it, a honeypot uses fake vulnerable systems to lure attackers so you can study how they operate.
Topics
Community Discussion
No community discussion yet for this question.