CompTIA Security+ (SY0-701)General Security ConceptsMedium
A security team places a fake set of database credentials inside a production configuration file that is never actually used. If those credentials are ever used to attempt a login, an alert is triggered. What is this technique called?
- ASandboxing
- BDigital signature
- CHoneynet
- DHoneytoken
Show answer & explanationAnswer & explanation
Correct answer: D. Honeytoken
A honeytoken is a piece of fake data, such as bogus credentials, planted to detect unauthorized access; any use of it indicates malicious activity because legitimate users would never use it.
Why the other options are wrong
- A. Sandboxing isolates code execution for analysis, unrelated to fake credentials.
- B. A digital signature verifies authenticity and integrity, not deception.
- C. A honeynet is a network of decoy systems, not a single fake data item.
Honeytoken
A piece of fake data (credentials, files, database entries) planted to detect unauthorized access when the data is used.
- Part of deception technology alongside honeypots and honeynets
- Triggers alerts on any use since no legitimate reason exists
- Cheap, low-maintenance detection mechanism
Memory trick: Token = bait, not a whole network