How can potential attacker activities be identified without affecting production servers?
Which of the following can be used to identify potential attacker activities without affecting production servers?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests your understanding of deception-based security controls, specifically that honeypots isolate attacker interaction from real production systems to safely gather intelligence.
A honeypot is a decoy system designed to lure attackers away from production assets while enabling security teams to study their techniques. The community overwhelmingly agrees that honeypots are the correct answer for identifying attacker activity without impacting live operations.
Some candidates choose Video surveillance, reasoning that physical monitoring doesn't touch servers, but the question focuses on identifying cyber attacker activities on network systems, not physical intrusions.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A honeypot is a deliberately vulnerable decoy system deployed to attract and study attackers without exposing real production assets. Because it is isolated from critical infrastructure, all attacker activity can be logged and analyzed safely. This makes it the ideal tool for identifying potential attacker behavior with zero impact on production servers.Why the Other Options Are Wrong
Video surveillance is a physical security control and does not detect or analyze cyber attacker activities on network systems. Zero Trust is an architectural framework focused on continuous verification and least-privilege access, not a detection tool. Geofencing restricts or monitors activity based on geographic boundaries but does not actively lure or study attacker behavior on systems.Community Comment Notes
Comment [1] correctly defines a honeypot as a decoy to detect, deflect, and study hacking attempts, aligning perfectly with the correct answer. Comment [3] raises a thoughtful concern about honeypots consuming resources, but honeypots are typically lightweight, isolated VMs or containers that do not interfere with production workloads. The community consensus (100% votes for A) confirms that honeypot is the universally accepted answer.Official Reference
Exam Strategy
When a question asks about detecting attacker activity without impacting production, think of deception technology like honeypots and honeynets. Eliminate physical security and architectural frameworks first, as they do not serve as active detection decoys.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →