CompTIA Network+ (N10-009)Network SecurityHard
A security team wants to observe and study attacker techniques and tools without exposing production systems to real risk. They deploy an isolated decoy server running intentionally vulnerable services and populated with fake sensitive data, then closely monitor all traffic and activity directed at it. Which security tool have they implemented?
- ANetwork Access Control (NAC)
- BHoneypot
- CIntrusion Detection System (IDS)
- DScreened subnet (DMZ)
Show answer & explanationAnswer & explanation
Correct answer: B. Honeypot
A honeypot is a decoy system deliberately made to look vulnerable and attractive to attackers, deployed in isolation to lure, observe, and study malicious activity without risking real assets. NAC enforces device compliance before granting access, an IDS passively detects intrusions across the real network, and a screened subnet (DMZ) hosts legitimately exposed public-facing services rather than decoys.
Why the other options are wrong
- A. NAC controls which devices are allowed onto the network, not a decoy system.
- C. An IDS monitors real traffic for signs of intrusion but isn't itself a decoy.
- D. A screened subnet (DMZ) hosts real public-facing services, not fake decoy systems.
Honeypot
An isolated decoy system designed to appear vulnerable, used to attract attackers so their techniques can be observed and studied without risking production assets.
- Deployed on its own isolated segment
- Populated with fake data and vulnerable-looking services
- A group of honeypots forms a honeynet
Memory trick: Sweet decoy traps the bee (attacker).