Soru

Zorluk: OrtaDeception and Disruption Technologies

A security operations team wants to detect unauthorized lateral movement and Kerberoasting attacks within their Active Directory domain without modifying host configurations or deploying dedicated virtual servers. The team creates a fake domain account configured with a Service Principal Name (SPN) and monitors domain controller logs for any Ticket Granting Service (TGS) request targeting this account. Which of the following deception technologies has the team deployed?

  1. HoneytokenCevap
  2. B
    Low-interaction honeypot
  3. C
    DNS sinkhole
  4. D
    Inline firewall rule

Cevap

Honeytoken
The implementation of a fake Active Directory account with a Service Principal Name specifically designed to trigger alerts upon access represents a honeytoken. Honeytokens are decoy credentials, files, or database records placed within production environments to lure attackers and trigger high-confidence alerts when queried or compromised.

Adım Adım Çözüm

1
Analyze the scenario details and requirements.
The team injected a fake credential asset (a decoy SPN) into Active Directory to alert when queried by adversaries.
Identifying the type of decoy asset helps distinguish between host-level decoys and data-level decoys.
2
Evaluate the mechanism against deception technology classifications.
Decoy data items such as fake database records, fake credentials, or fake SPNs are classified as honeytokens.
Honeytokens monitor unauthorized access to non-production data assets placed directly within existing systems.
3
Differentiate from honeypots, sinkholes, and preventive security controls.
No virtual server or service emulation is deployed (ruling out honeypots), and no network traffic filtering occurs (ruling out sinkholes and firewalls).
Honeypots require dedicated host or service emulation, whereas honeytokens are lightweight data artifacts.

Anahtar Kavram

Deception Technologies - Honeytokens
Bu soruyu puanla