Which Defensive Technique Lures and Detects Malicious Insiders?

Which of the following techniques would attract the attention of a malicious attacker in an insider threat scenario?

  1. Creating a false text file in /docs/salaries Source Reference Answer
  2. Setting weak passwords in /etc/shadow
  3. Scheduling vulnerable jobs in /etc/crontab
  4. Adding a fake account to /etc/passwd

Community Votes

A
77%
B
23%

77% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

It tests your ability to differentiate between intentional defensive deception strategies and accidental security misconfigurations that compromise system integrity.

This question examines the use of deception technology, specifically honeyfiles, to proactively monitor and detect unauthorized access by insider threats. The candidate community overwhelmingly supports option A, recognizing that controlled decoys serve as effective monitoring tools rather than actual security vulnerabilities.

Candidates frequently choose option B, incorrectly assuming that poor security hygiene like weak passwords naturally attracts malicious actors. This mistake confuses a genuine system vulnerability with a controlled, monitored defensive measure designed specifically for threat detection.

Community Discussion (7 comments)

Anyio 👍 3 Selected: A
A. Creating a false text file in /docs/salaries Explanation: This technique is an example of setting up a honeypot or decoy. A false text file labeled something enticing like "salaries" could attract the attention of an insider threat. If the malicious insider attempts to access it, their behavior can be monitored or flagged. This method does not compromise system security but instead acts as bait to detect malicious activity. Other Options: B. Setting weak passwords in /etc/shadow: Weak passwords would compromise system security and invite external attackers rather than serving as a monitoring tactic. C. Scheduling vulnerable jobs in /etc/crontab: This could lead to system exploitation and does not serve as a targeted method for insider threat detection.
Eracle 👍 4 Selected: A
The correct answer is A, not B because configuring weak passwords would compromise the security of the system, exposing it to real risks.
jbmac 👍 1 Selected: B
The correct answer is: B. Setting weak passwords in /etc/shadow Explanation: In an insider threat scenario, one of the most likely techniques to attract the attention of a malicious attacker is setting weak passwords in the /etc/shadow file. This file stores password hashes for user accounts, and if an insider sets weak passwords, attackers can potentially crack these passwords through brute force or other methods. Once an attacker has access to weak passwords, they can escalate privileges, access sensitive information, or exploit the system for malicious purposes.
laternak26 👍 2 Selected: A
Creating a false text file in /docs/salaries attracts insiders, which usually looking for sensitive information.
Kokoh23 👍 1 Selected: A
This question is from a security operations prospective and focuses on how to catch an insider threat. #1 Never set a weak password. This could be exploited by an actual External Malicious actor. #2 Its the decoy file (A.k.a) Honey file principle. Using fake files that are highly monitored to see which accounts engage with them. Subsequently launching an investigation as to why that person was accessing the file. (Create a false text file)
ec80b38 👍 1 Selected: B
In an insider threat scenario, setting weak passwords in the system's password file (/etc/shadow) would be particularly attractive to a malicious attacker because:
AndyK2 👍 1 Selected: B
In an insider threat scenario, setting weak passwords in the system's password file (/etc/shadow) would be particularly attractive to a malicious attacker because: Weak passwords create an easy entry point for unauthorized access It provides a method of persistent system compromise The action can be done subtly without immediate detection Weak passwords can potentially be used to escalate privileges It exploits inherent system authentication mechanisms

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Concept: Deception Technology and Honeyfiles

Creating deceptive assets like honeyfiles or honeypots is a recognized proactive defense mechanism in modern security operations. By placing a highly attractive but non-sensitive file in a logical location, administrators can establish strict monitoring and logging around that specific path. When a malicious insider accesses the file, the alert triggers immediate investigation, allowing organizations to identify compromised accounts and trace internal data exfiltration attempts without exposing real sensitive data.

Why Option A Is Correct

Option A directly implements a deception control. As noted by community experts, this technique acts as digital bait that does not weaken the host system’s security posture. Instead, it shifts the focus to behavioral analytics and audit trails, making it ideal for identifying insiders who bypass normal access controls to search for high-value targets.

Why Other Options Fail

Options B, C, and D represent actual security misconfigurations rather than defensive tactics. Placing weak passwords in /etc/shadow or adding fake accounts to /etc/passwd degrades authentication security and creates exploitable entry points for both internal and external adversaries. Similarly, scheduling vulnerable cron jobs introduces unnecessary attack surfaces. These actions violate the principle of least privilege and secure configuration management, which are foundational to CompTIA Security+ standards.

Community Validation

The strong community preference for A aligns with industry best practices on deception technology. Candidates correctly emphasize that monitoring decoy engagement provides actionable intelligence for incident response, whereas deliberately introducing weaknesses merely invites uncontrolled compromise.

Official Reference

Exam Strategy

When analyzing insider threat scenarios, always prioritize active monitoring and deception controls over passive system configurations. Carefully distinguish between intentional defensive measures designed to catch attackers and accidental security gaps that actually increase risk, as exam writers frequently test this distinction through realistic operational contexts.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide