CompTIA Security+ (SY0-701)General Security ConceptsMedium
A security team deploys multiple interconnected fake servers, workstations, and network shares that mimic a real corporate environment to study attacker techniques and tools in detail. What is this deployment called?
- ASinkhole
- BHoneytoken
- CHoneynet
- DSandbox
Show answer & explanationAnswer & explanation
Correct answer: C. Honeynet
A honeynet is a network of interconnected honeypots designed to simulate an entire environment, allowing defenders to observe and analyze attacker behavior across multiple systems.
Why the other options are wrong
- A. A DNS sinkhole redirects malicious traffic to a controlled server, unrelated to a decoy network.
- B. A honeytoken is a single fake credential or data element, not an entire network of decoy systems.
- D. A sandbox is an isolated environment for safely executing suspicious code, not a decoy network.
Honeynet
A network of multiple honeypots designed to appear as a realistic production environment, used to study attacker behavior in depth.
- Composed of multiple interconnected honeypots
- Provides broader attacker behavior analysis than a single honeypot
- Used for threat intelligence gathering
Memory trick: One honeypot is a trap; a honeynet is a whole fake town.