CompTIA Security+ (SY0-701)General Security ConceptsMedium

A security team deploys multiple interconnected fake servers, workstations, and network shares that mimic a real corporate environment to study attacker techniques and tools in detail. What is this deployment called?

  1. ASinkhole
  2. BHoneytoken
  3. CHoneynet
  4. DSandbox
Show answer & explanation

Correct answer: C. Honeynet

A honeynet is a network of interconnected honeypots designed to simulate an entire environment, allowing defenders to observe and analyze attacker behavior across multiple systems.

Why the other options are wrong

  • A. A DNS sinkhole redirects malicious traffic to a controlled server, unrelated to a decoy network.
  • B. A honeytoken is a single fake credential or data element, not an entire network of decoy systems.
  • D. A sandbox is an isolated environment for safely executing suspicious code, not a decoy network.

Honeynet

A network of multiple honeypots designed to appear as a realistic production environment, used to study attacker behavior in depth.

  • Composed of multiple interconnected honeypots
  • Provides broader attacker behavior analysis than a single honeypot
  • Used for threat intelligence gathering

Memory trick: One honeypot is a trap; a honeynet is a whole fake town.

More General Security Concepts questions