Question

Difficulty: HardDeception and Disruption Technologies

An enterprise security architecture team is deploying a deception and disruption strategy within an operational technology (OT) network to detect unauthorized lateral movement and internal service discovery. The environment includes legacy industrial control systems, programmable logic controllers (PLCs), and human-machine interfaces (HMIs). Which of the following implementation practices should the team select to achieve high-fidelity threat detection while preventing operational disruption to production systems? (Select TWO.)

  1. Deploying low-interaction honeypots on isolated subnets that emulate industrial control protocols to generate alerts upon any inbound connection attempt.Answer
  2. Placing decoy credentials and fake network path references into administrative host memory to serve as breadcrumbs leading attackers toward decoy systems.Answer
  3. C
    Configuring low-interaction honeypots inline between production PLCs and network switches to filter unauthorized industrial protocol traffic in real time.
  4. D
    Deploying active vulnerability scanning software on deception nodes to automatically execute remediation scripts on production PLCs when probes occur.

Answer

The correct practices are deploying low-interaction honeypots on isolated subnets that emulate industrial control protocols and placing decoy credentials or network references in administrative host memory as breadcrumbs.
Deploying low-interaction honeypots on isolated subnets that emulate industrial protocols provides a safe, non-intrusive method for capturing unauthorized network discovery in OT environments without placing real hardware at risk. Furthermore, placing decoy credentials and fake path references in host memory acts as breadcrumbs that steer adversaries away from production assets and into monitored deception traps during lateral movement.

Step-by-Step Solution

1
Analyze the operational constraints and deception objectives in an industrial control environment.
Identified the need for non-disruptive detection mechanisms capable of capturing adversary reconnaissance and lateral movement without impacting production PLCs.
Legacy OT systems are highly sensitive to network traffic anomalies and cannot support intrusive inline controls.
2
Evaluate the low-interaction honeypot deployment strategy.
Isolated low-interaction honeypots simulating industrial protocols safely trap unauthorized connection attempts and yield high-fidelity alerts since legitimate traffic should never contact these decoy nodes.
Low-interaction honeypots reduce resource usage and eliminate operational risk to real physical equipment.
3
Evaluate host-based deception techniques using breadcrumbs.
Planting decoy credentials and fake network paths on host systems acts as breadcrumbs that direct attackers performing memory scraping or configuration enumeration toward deception traps.
Breadcrumbs manipulate adversary decision-making during post-exploitation reconnaissance.
4
Identify misconceptions regarding deception technology roles.
Rejected options that misclassify honeypots as inline filtering mechanisms or active vulnerability remediation agents.
Deception technology operates as a detective/intelligence control rather than an inline preventive firewall or active vulnerability management system.

Key Concept

Deception and Disruption Architecture in Specialized Networks
Rate this question