nerdexam
CompTIA

SY0-701 · Question #565

Which of the following would most likely be deployed to obtain and analyze attacker activity and techniques?

The correct answer is C. Honeypot. A honeypot is a deliberately vulnerable decoy system designed to lure attackers, then monitor and record everything they do - making it the ideal tool for studying attacker behavior, tactics, and techniques in a controlled environment. Why the distractors are wrong: A. Firewall…

Submitted by suresh_in· Mar 6, 2026Security operations

Question

Which of the following would most likely be deployed to obtain and analyze attacker activity and techniques?

Options

  • AFirewall
  • BIDS
  • CHoneypot
  • DLayer 3 switch

How the community answered

(35 responses)
  • A
    3% (1)
  • B
    6% (2)
  • C
    89% (31)
  • D
    3% (1)

Explanation

A honeypot is a deliberately vulnerable decoy system designed to lure attackers, then monitor and record everything they do - making it the ideal tool for studying attacker behavior, tactics, and techniques in a controlled environment.

Why the distractors are wrong:

  • A. Firewall - blocks or filters traffic based on rules; it prevents attacks but doesn't study them.
  • B. IDS (Intrusion Detection System) - detects and alerts on suspicious activity on real systems, but its purpose is protection/alerting, not behavioral analysis of attacker methodology.
  • D. Layer 3 switch - a network device that routes traffic between subnets; it has no security monitoring function at all.

Memory tip: Think of a honeypot like a "bait trap" - just as a bear trap uses honey to lure and catch a bear so you can study it, a honeypot uses fake vulnerable systems to lure attackers so you can study how they operate.

Topics

#Honeypots#Threat Intelligence#Attacker Analysis#Security Tools

Community Discussion

No community discussion yet for this question.

Full SY0-701 Practice