Which Deception Method Uses a Fake Credential Spreadsheet?

A security analyst created a fake account and saved the password in a non-readily accessible directory in a spreadsheet. An alert was also configured to notify the security team if the spreadsheet is opened. Which of the following best describes the deception method being deployed?

  1. Honeypot
  2. Honeyfile
  3. Honeytoken Source Reference Answer
  4. Honeynet

Community Votes

C
56%
B
44%

56% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests whether you can identify a honeytoken by its function (fake credentials acting as digital bait) rather than its storage format, preventing candidates from falling for the spreadsheet distractor.

This question evaluates understanding of deception technologies used to detect unauthorized access, highlighting the distinction between decoy systems and decoy data. While community debate exists between honeyfiles and honeytokens, official guidance classifies embedded fake credentials with activity monitoring as honeytokens.

Many candidates incorrectly choose Honeyfile because the detection trigger activates upon opening a specific document. This oversight ignores the core objective: tracking the misuse of fabricated credentials, which definitively categorizes the setup as a honeytoken.

Community Discussion (4 comments)

Teliyah21 👍 2 Selected: B
B it is a honey file
drew81 👍 1 Selected: C
Honeytoken refers to any decoy data or token inserted into a system (fake user account, data base record, or any other type of digital bait. When interacted with, indicates a compromise or unauthorized access.
Commando9800 👍 2 Selected: B
The trigger happens when the spreadsheet is opened, so its a Honeyfile
test_arrow 👍 4 Selected: C
C. Honeytoken Explanation: ✔ A honeytoken is a decoy piece of data (e.g., fake credentials, database records, or files) designed to detect unauthorized access. ✔ In this scenario, the analyst created a fake account (credentials) and stored them in a hidden spreadsheet, setting up an alert when accessed. ✔ This helps identify malicious activity if an attacker discovers and attempts to use the credentials. Why not the other options? A. Honeypot – A decoy system or server designed to lure attackers, not a single credential or file. B. Honeyfile – A fake document (e.g., a sensitive-looking spreadsheet or PDF), whereas this scenario is about credentials rather than just a document. D. Honeynet – A network of multiple honeypots, not a single deception mechanism like a honeytoken.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Understanding Deception Technologies

Deception technology involves deploying artificial assets to detect, deflect, or study malicious activities. In cybersecurity exams like SY0-701, distinguishing between these artifacts requires focusing on their scope and composition rather than their delivery method.

Why Honeytoken is the Correct Answer

A honeytoken is a piece of decoy data, such as fake credentials, database records, API keys, or certificates, intentionally placed within production environments to signal unauthorized access. As highlighted in community discussions, users like drew81 correctly note that honeytokens serve as digital bait designed to detect compromise when interacted with. The scenario explicitly mentions a fake account and stored password paired with an open-alert mechanism, perfectly matching the honeytoken definition. Community expert test_arrow further clarifies that any fabricated credential deployed to monitor usage falls strictly under this category.

Why the Other Options Are Incorrect

  • Honeyfile: Often confused due to the spreadsheet trigger, a honeyfile is strictly a decoy document meant to attract attackers searching for sensitive files. However, because the primary bait here is authentication data rather than just a tempting file, CompTIA classifies it as a honeytoken.
  • Honeypot: A honeypot is an entire decoy system or server configured to appear vulnerable, used to study attacker tactics at a host level. It does not apply to a single file or credential set.
  • Honeynet: A honeynet expands the honeypot concept to an entire simulated network segment containing multiple systems. This is far too broad for a localized credential deployment.

Navigating the Exam Debate

The SY0-701 exam frequently tests nuanced definitions. When a question emphasizes fake credentials, tokens, or database entries triggering alerts, honeytoken is the authoritative answer. Relying on the container leads to the common honeyfile trap.

Official Reference

  • CompTIA Security+ SY0-701 Official Study Guide - Domain 1.3: Threats and Vulnerabilities
  • NIST Special Publication 800-115: Technical Guide to Information Security Testing and Assessment
  • MITRE ATT&CK Framework - Deception Techniques

Exam Strategy

When answering deception technology questions, ignore the file format or storage location and focus entirely on what the artifact represents and how it functions. If fake credentials, API keys, or database rows are deployed to trigger alerts, immediately select honeytoken; reserve honeypots and honeynets for descriptions involving entire systems or network topologies.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide