Soru

Zorluk: ZorNetwork Security Monitoring and Alerting

During network security monitoring of a segmented cloud environment, an analyst receives an automated Network Intrusion Detection System (NIDS) alert indicating that an internal deception host (honeypot) has initiated outbound network connections toward an unknown external address. A team member suggests modifying network routing policies to use this honeypot host as an inline security filter for all outbound enterprise traffic to block unauthorized connections. Which of the following best explains why this recommendation represents a fundamental misunderstanding of network monitoring and deception controls?

  1. Honeypots are designed purely as threat intelligence and detective monitoring tools, not inline preventive traffic-filtering mechanisms.Cevap
  2. B
    Honeypots function primarily as inline preventive controls that automatically sanitize and forward legitimate user traffic during an incident.
  3. C
    Network intrusion detection systems automatically reconfigure honeypots into corrective inline firewalls upon triggering high-severity alerts.
  4. D
    Deploying a Web Application Firewall rule on perimeter routers is the required primary mitigation to block outbound network IP connections from host machines.

Cevap

Honeypots are designed purely as threat intelligence and detective monitoring tools, not inline preventive traffic-filtering mechanisms.
Deception technologies, such as honeypots, are specialized detective security controls placed in network environments to lure attackers, detect unauthorized access attempts, and capture threat intelligence. Because any traffic interacting with a honeypot is inherently suspicious, these assets are strictly isolated and monitored passively. They are not production gateways or inline filtering systems, and routing legitimate enterprise network traffic through them introduces severe security risks and operational degradation.

Adım Adım Çözüm

1
Analyze the role of the security asset identified in the alert.
The target asset is a honeypot (deception technology) within a monitored network segment.
Honeypots have no legitimate production duties and exist strictly to detect, trap, and monitor unauthorized interactions.
2
Evaluate the proposed operational change.
Routing production outbound traffic through a honeypot treats a detective deception control as an inline preventive firewall.
Honeypots are not hardened or designed to function as high-throughput inline filtering gateways for production environments.
3
Select the option that correctly contrasts deception controls with inline filtering.
The correct response highlights that honeypots function as detective and intelligence-gathering tools rather than inline filtering appliances.
Proper security architecture distinguishes passive detective monitoring tools from active preventive traffic-filtering controls.

Anahtar Kavram

Honeypot Functionality vs. Inline Defense Controls
Tahmini Süre:1m 30s
Bu soruyu puanla