How can potential attacker activities be identified without affecting production servers?

Which of the following can be used to identify potential attacker activities without affecting production servers?

  1. Honeypot Source Reference Answer
  2. Video surveillance
  3. Zero Trust
  4. Geofencing

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests your understanding of deception-based security controls, specifically that honeypots isolate attacker interaction from real production systems to safely gather intelligence.

A honeypot is a decoy system designed to lure attackers away from production assets while enabling security teams to study their techniques. The community overwhelmingly agrees that honeypots are the correct answer for identifying attacker activity without impacting live operations.

Some candidates choose Video surveillance, reasoning that physical monitoring doesn't touch servers, but the question focuses on identifying cyber attacker activities on network systems, not physical intrusions.

Community Discussion (4 comments)

123456789User 👍 10 Selected: A
Honeypot - a network-attached system set up as a decoy to lure cyber attackers and detect, deflect and study hacking attempts on systems.
Osechabelo 👍 5
A. Honeypot • Attract the bad guys - And trap them there
e43d250 👍 1 Selected: A
A. Honeypot
Shadyshinies 👍 2
Would that not require servers and resources to do a honeypot which then interrupts server production by extension. I feel like b would make sense since it wouldn't affect servers and can detect attackers. Idk though

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A honeypot is a deliberately vulnerable decoy system deployed to attract and study attackers without exposing real production assets. Because it is isolated from critical infrastructure, all attacker activity can be logged and analyzed safely. This makes it the ideal tool for identifying potential attacker behavior with zero impact on production servers.

Why the Other Options Are Wrong

Video surveillance is a physical security control and does not detect or analyze cyber attacker activities on network systems. Zero Trust is an architectural framework focused on continuous verification and least-privilege access, not a detection tool. Geofencing restricts or monitors activity based on geographic boundaries but does not actively lure or study attacker behavior on systems.

Community Comment Notes

Comment [1] correctly defines a honeypot as a decoy to detect, deflect, and study hacking attempts, aligning perfectly with the correct answer. Comment [3] raises a thoughtful concern about honeypots consuming resources, but honeypots are typically lightweight, isolated VMs or containers that do not interfere with production workloads. The community consensus (100% votes for A) confirms that honeypot is the universally accepted answer.

Official Reference

Exam Strategy

When a question asks about detecting attacker activity without impacting production, think of deception technology like honeypots and honeynets. Eliminate physical security and architectural frameworks first, as they do not serve as active detection decoys.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide