Which Defensive Technique Lures and Detects Malicious Insiders?
Which of the following techniques would attract the attention of a malicious attacker in an insider threat scenario?
Community Votes
77% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
It tests your ability to differentiate between intentional defensive deception strategies and accidental security misconfigurations that compromise system integrity.
This question examines the use of deception technology, specifically honeyfiles, to proactively monitor and detect unauthorized access by insider threats. The candidate community overwhelmingly supports option A, recognizing that controlled decoys serve as effective monitoring tools rather than actual security vulnerabilities.
Candidates frequently choose option B, incorrectly assuming that poor security hygiene like weak passwords naturally attracts malicious actors. This mistake confuses a genuine system vulnerability with a controlled, monitored defensive measure designed specifically for threat detection.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept: Deception Technology and Honeyfiles
Creating deceptive assets like honeyfiles or honeypots is a recognized proactive defense mechanism in modern security operations. By placing a highly attractive but non-sensitive file in a logical location, administrators can establish strict monitoring and logging around that specific path. When a malicious insider accesses the file, the alert triggers immediate investigation, allowing organizations to identify compromised accounts and trace internal data exfiltration attempts without exposing real sensitive data.Why Option A Is Correct
Option A directly implements a deception control. As noted by community experts, this technique acts as digital bait that does not weaken the host system’s security posture. Instead, it shifts the focus to behavioral analytics and audit trails, making it ideal for identifying insiders who bypass normal access controls to search for high-value targets.Why Other Options Fail
Options B, C, and D represent actual security misconfigurations rather than defensive tactics. Placing weak passwords in/etc/shadow or adding fake accounts to /etc/passwd degrades authentication security and creates exploitable entry points for both internal and external adversaries. Similarly, scheduling vulnerable cron jobs introduces unnecessary attack surfaces. These actions violate the principle of least privilege and secure configuration management, which are foundational to CompTIA Security+ standards.Community Validation
The strong community preference for A aligns with industry best practices on deception technology. Candidates correctly emphasize that monitoring decoy engagement provides actionable intelligence for incident response, whereas deliberately introducing weaknesses merely invites uncontrolled compromise.Official Reference
Exam Strategy
When analyzing insider threat scenarios, always prioritize active monitoring and deception controls over passive system configurations. Carefully distinguish between intentional defensive measures designed to catch attackers and accidental security gaps that actually increase risk, as exam writers frequently test this distinction through realistic operational contexts.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →