CompTIA Security+ (SY0-701)Security OperationsEasy

A security team deploys a server on an isolated VLAN that mimics a production database, complete with fake customer records. The system has no legitimate business use and exists solely to attract and monitor attacker activity. Which type of control has been implemented?

  1. AJump box
  2. BBastion host
  3. CHoneypot
  4. DSandbox
Show answer & explanation

Correct answer: C. Honeypot

A honeypot is a decoy system designed to lure attackers away from real assets while allowing defenders to observe tactics and techniques. Sandboxes analyze suspicious files in isolation rather than acting as bait, and jump boxes/bastion hosts are legitimate access-control chokepoints, not decoys.

Why the other options are wrong

  • A. A jump box is a hardened intermediary for legitimate administrative access.
  • B. A bastion host is a hardened, exposed server for controlled access, not bait.
  • D. A sandbox isolates and analyzes code behavior, it is not a decoy.

Honeypot

A decoy system or resource intentionally exposed to attract attackers, allowing defenders to study techniques and divert attention from real assets.

  • Contains no real production data
  • Used for threat intelligence and early warning
  • A honeynet is a network of multiple honeypots

Memory trick: Honey attracts the bear (attacker) away from the hive (real data).

More Security Operations questions