Soru

Zorluk: OrtaDeception and Disruption Technologies

A security analyst places decoy configuration files containing dummy server hostnames and fake database connection parameters onto several developer endpoints. The intention is that an unauthorized intruder performing local credential harvesting will follow these planted traces toward a monitored decoy system. Which of the following deception and disruption technologies is primarily being utilized on the developer endpoints?

  1. BreadcrumbCevap
  2. B
    Honeynet
  3. C
    Low-interaction honeypot
  4. D
    Inline intrusion prevention system

Cevap

Breadcrumbs are host-based deception artifacts (such as fake database strings, saved connections, or registry keys) placed on real endpoints to entice adversaries into exposing their presence by targeting monitored decoys.
Breadcrumbs consist of intentionally placed decoy information—such as fake registry entries, stored connection paths, mapped drives, or configuration files—on real production devices. They serve as lure trails to trick adversaries performing internal reconnaissance into revealing themselves by contacting decoy systems.

Adım Adım Çözüm

1
Analyze the action performed on the endpoints
Fake configuration files and server parameters were planted on legitimate workstations.
Identifying the nature of the placed artifact helps differentiate between decoy targets and decoy pointers.
2
Determine the operational purpose of the artifact
The artifacts act as fake trails to guide attackers from production hosts toward decoy infrastructure.
Artifacts designed to lead adversaries to deception targets fit the definition of breadcrumbs.
3
Match the defense mechanism to standard deception technology definitions
Breadcrumbs serve as the trail/pointer mechanisms on production systems.
This distinguishes breadcrumb artifacts from honeypots (the decoy targets themselves) or honeynets (entire decoy networks).

Anahtar Kavram

Deception Technologies - Breadcrumbs vs. Decoy Systems
Bu soruyu puanla