Soru

Zorluk: OrtaDeception and Disruption Technologies

An organization aims to enhance its threat detection capabilities against internal lateral movement and credential theft within a cloud-native environment. The security team decides to deploy deception technologies to lure attackers into revealing their presence without exposing actual production assets. Which of the following techniques should the security team implement to meet these objectives? (Select TWO).

  1. Honeytokens embedded within deployment configuration files to trigger alerts when invokedCevap
  2. Low-interaction honeypots disguised as vulnerable microservice API endpoints to detect unauthorized probesCevap
  3. C
    Inline network intrusion prevention systems configured to dynamically route suspicious production traffic into decoy environments
  4. D
    Network access control policies configured to quarantine unauthorized endpoints following authentication failures

Cevap

The organization should implement honeytokens embedded within configuration files and low-interaction honeypots disguised as vulnerable API endpoints.
Honeytokens embedded in configuration files and low-interaction honeypots simulating API endpoints are direct implementations of deception technology. Honeytokens alert security operations when unauthorized entities attempt to use fake tokens, while low-interaction honeypots capture reconnaissance probes safely without risking production data.

Adım Adım Çözüm

1
Identify the primary objective of active deception deployment
The objective is to deploy deception resources that attract adversaries and detect unauthorized internal activities without exposing real assets.
Deception technologies work by establishing non-production lures and decoys that generate high-fidelity detection signals upon interaction.
2
Evaluate candidate deception components
Honeytokens provide immediate detection when stolen credentials are used, while low-interaction honeypots simulate API endpoints to capture initial reconnaissance.
Both methods act directly as lures to trap attackers early in the lateral movement or discovery phase.
3
Distinguish deception mechanisms from traditional security controls
Inline IPS devices and NAC policies are active preventive and network enforcement defenses, not deception lures.
Traditional defensive controls enforce policy and filter production traffic rather than intentionally offering fake target assets.

Anahtar Kavram

Deception technologies strategically deploy fake assets, credentials, or services (such as honeytokens and honeypots) to allure adversaries and detect unauthorized activity early in the attack lifecycle.
Bu soruyu puanla