Identifying Decoy Systems for Reconnaissance Detection
A company wants to get alerts when others are researching and doing reconnaissance on the company. One approach would be to host a part of the infrastructure online with known vulnerabilities that would appear to be company assets. Which of the following describes this approach?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The scenario describes an intentional trap with known vulnerabilities to detect research; this is the textbook definition of a honeypot, not passive monitoring or bug bounty programs.
A honeypot is a decoy system designed to attract attackers by appearing vulnerable, allowing organizations to monitor reconnaissance activities. This question tests the ability to distinguish active deception techniques from other security controls.
Learners often confuse honeypots with DNS sinkholes (used for malware redirection) or watering holes (compromising legitimate sites used by targets). The key differentiator is the 'decoy asset' aspect.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A honeypot is specifically defined as a computer system or network segment that is set up to attract and deceive attackers. By hosting infrastructure that appears to be a real company asset but contains known vulnerabilities, administrators can observe attacker behavior during the reconnaissance phase without risking actual production data. This aligns perfectly with the goal of getting alerts when others are researching the company.Why the Other Options Are Wrong
A watering hole attack involves compromising a legitimate website frequently visited by the target audience to infect them, rather than acting as a decoy for reconnaissance. A bug bounty program is a crowdsourced approach where external researchers find vulnerabilities in exchange for rewards, which is a legitimate security practice, not a deceptive trap. A DNS sinkhole redirects malicious domain requests to a controlled server to prevent infection, typically used after an attack has initiated or for botnet mitigation, not for detecting initial reconnaissance on assets.Community Comment Notes
The community consensus strongly supports D, with learners noting that honeypots are "decoy systems" designed to entice attackers. One user humorously referenced the concept of a "pot o' honey," reinforcing the mnemonic for the term. The high vote count indicates broad agreement that this is a straightforward definition question.Official Reference
Exam Strategy
When you see keywords like 'decoy,' 'trap,' 'attract attackers,' or 'known vulnerabilities' in a non-production environment, think Honeypot. Differentiate it from Honeynet (a network of honeypots) and Honeytoken (fake data).
Frequently Asked Questions
What is the difference between a honeypot and a honeynet?
A honeypot is a single decoy system, while a honeynet is a network containing multiple honeypots to simulate a larger environment.
Is a honeypot considered part of Active Defense?
Yes, honeypots are an active defense mechanism because they interact with and mislead attackers, unlike passive monitoring tools.