Question

Difficulty: EasyDeception and Disruption Technologies

A system administrator places a fake spreadsheet named confidential_salaries.xlsx containing fictitious employee records onto a corporate file share. The administrator configures security software to trigger an immediate alert whenever this file is opened or accessed. Which of the following deception technologies has the administrator implemented?

  1. HoneyfileAnswer
  2. B
    Honeynet
  3. C
    DNS sinkhole
  4. D
    Stateful firewall

Answer

Honeyfile
The correct answer is a honeyfile. A honeyfile is an intentionally placed decoy file containing synthetic or bait information. Because legitimate business processes do not require accessing this dummy file, any open or read activity immediately alerts security analysts to suspicious or unauthorized internal reconnaissance.

Step-by-Step Solution

1
Analyze the scenario details
The administrator deployed a single dummy file with alerting configured to detect unauthorized file access.
Deception controls utilize decoy assets within an environment to lure unauthorized actors and provide early warning of an intrusion.
2
Identify the deception technology category
A fake file used as a decoy to catch unauthorized users accessing sensitive storage locations is defined as a honeyfile.
Honeyfiles specifically monitor file shares and data repositories for unauthorized reads or copies.

Key Concept

Honeyfile Deception Control
Rate this question