Identifying Decoy Systems for Reconnaissance Detection

Answer Correct answer: D — Deploying a honeypot allows the organization to monitor and alert on attacker reconnaissance by presenting a vulnerable decoy asset.

A company wants to get alerts when others are researching and doing reconnaissance on the company. One approach would be to host a part of the infrastructure online with known vulnerabilities that would appear to be company assets. Which of the following describes this approach?

  1. Watering hole
  2. Bug bounty
  3. DNS sinkhole
  4. Honeypot Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The scenario describes an intentional trap with known vulnerabilities to detect research; this is the textbook definition of a honeypot, not passive monitoring or bug bounty programs.

A honeypot is a decoy system designed to attract attackers by appearing vulnerable, allowing organizations to monitor reconnaissance activities. This question tests the ability to distinguish active deception techniques from other security controls.

Learners often confuse honeypots with DNS sinkholes (used for malware redirection) or watering holes (compromising legitimate sites used by targets). The key differentiator is the 'decoy asset' aspect.

Community Discussion (3 comments)

1403ad2 👍 12 Selected: D
choose D 2024-20-2 On Test and passed with 80
AspiringNerd 👍 1 Selected: D
Just think of Poo getting his head stuck in a pot o' honey :]
Hs1208 👍 4 Selected: D
A honeypot is a decoy system or network designed to attract and detect attackers. It is intentionally set up with vulnerabilities to entice attackers into engaging with it.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A honeypot is specifically defined as a computer system or network segment that is set up to attract and deceive attackers. By hosting infrastructure that appears to be a real company asset but contains known vulnerabilities, administrators can observe attacker behavior during the reconnaissance phase without risking actual production data. This aligns perfectly with the goal of getting alerts when others are researching the company.

Why the Other Options Are Wrong

A watering hole attack involves compromising a legitimate website frequently visited by the target audience to infect them, rather than acting as a decoy for reconnaissance. A bug bounty program is a crowdsourced approach where external researchers find vulnerabilities in exchange for rewards, which is a legitimate security practice, not a deceptive trap. A DNS sinkhole redirects malicious domain requests to a controlled server to prevent infection, typically used after an attack has initiated or for botnet mitigation, not for detecting initial reconnaissance on assets.

Community Comment Notes

The community consensus strongly supports D, with learners noting that honeypots are "decoy systems" designed to entice attackers. One user humorously referenced the concept of a "pot o' honey," reinforcing the mnemonic for the term. The high vote count indicates broad agreement that this is a straightforward definition question.

Official Reference

Exam Strategy

When you see keywords like 'decoy,' 'trap,' 'attract attackers,' or 'known vulnerabilities' in a non-production environment, think Honeypot. Differentiate it from Honeynet (a network of honeypots) and Honeytoken (fake data).

Frequently Asked Questions

What is the difference between a honeypot and a honeynet?

A honeypot is a single decoy system, while a honeynet is a network containing multiple honeypots to simulate a larger environment.

Is a honeypot considered part of Active Defense?

Yes, honeypots are an active defense mechanism because they interact with and mislead attackers, unlike passive monitoring tools.

Related Analysis

← Back to SY0-601 Study Guide