Cisco Certified Support Technician (CCST) CybersecurityNetwork SecurityEasy

A cybersecurity team is setting up a honeypot to lure attackers and gather intelligence on their tactics, techniques, and procedures (TTPs). They want to make sure the honeypot appears as a legitimate, vulnerable system. Which of the following is the primary goal of deploying a honeypot in a network?

  1. ATo gather intelligence on attacker behavior
  2. BTo improve network performance
  3. CTo detect and deflect legitimate traffic
  4. DTo prevent all network intrusions
Show answer & explanation

Correct answer: A. To gather intelligence on attacker behavior

The primary goal of a honeypot is to act as a decoy to attract attackers, allowing security teams to observe and learn about their methods without risking actual production systems. This intelligence helps in improving overall security defenses.

Why the other options are wrong

  • B. Honeypots are a security tool and do not directly improve network performance.
  • C. Honeypots are designed to attract malicious traffic, not deflect legitimate traffic.
  • D. Honeypots do not prevent intrusions; they attract them to a controlled environment.

Honeypot

A security mechanism, typically a computer system or network segment, that is intentionally left vulnerable to attract and trap attackers to study their methods.

  • Acts as a decoy for attackers.
  • Gathers threat intelligence on TTPs.
  • Does not protect production systems directly, but provides insights.
  • Can be low-interaction or high-interaction.

Memory trick: Honeypot: A sweet trap for bad guys to learn their moves.

More Network Security questions