Question

Difficulty: Very hardDeception and Disruption Technologies

Match each active deception technology component on the left with its corresponding operational implementation function on the right.

  • HoneytokenA simulated credential, database entry, or API key embedded in production assets to trigger immediate alerts when used.
  • HoneynetAn entire high-interaction network segment containing multiple decoy systems used to observe adversary TTPs during lateral movement.
  • HoneyfileAn enticing decoy document stored on an audited enterprise file share to detect unauthorized access or data exfiltration attempts.
  • BreadcrumbA client-side artifact, such as a modified registry key or fake internal routing entry, planted to direct attackers toward decoy infrastructure.

Answer

Honeytoken pairs with simulated credential or API key; Honeynet pairs with high-interaction network segment of decoy systems; Honeyfile pairs with enticing decoy document on an audited file share; Breadcrumb pairs with client-side artifact planted to direct attackers toward decoy infrastructure.
Each deception technology matches its specific deployment role: Honeytokens represent fake credentials or data elements; Honeynets constitute multi-host decoy network environments; Honeyfiles are audited decoy documents; and Breadcrumbs serve as endpoint lure artifacts that steer threat actors toward decoy assets.

Step-by-Step Solution

1
Identify the data-centric deception element intended for credential/data harvesting detection.
Associate Honeytoken with fake credentials, database entries, or API keys embedded in production repositories.
Honeytokens focus specifically on monitoring unauthorized usage of non-production data values.
2
Differentiate macro-level network decoy environments from single-host artifacts.
Associate Honeynet with the complete simulated network segment containing multiple decoy systems.
Honeynets provide multi-system telemetry to observe broad attack vectors and lateral movement techniques.
3
Distinguish between monitored document files and endpoint redirection lures.
Associate Honeyfile with decoy documents stored on file shares, and Breadcrumb with host-level artifacts that direct attackers to honeypots.
Honeyfiles monitor data access directly, whereas breadcrumbs manipulate adversary reconnaissance paths on host systems.

Key Concept

Deception and Disruption Technologies in Active Defense Architecture
Rate this question