During network telemetry monitoring, a security technician observes an alert generated when an internal workstation attempts an unauthorized connection to a non-production server that contains simulated sensitive files and no real enterprise services. Which of the following network security monitoring concepts is actively being utilized in this scenario?
- A honeypot deployed as a deception mechanism to detect unauthorized internal accessCevap
- BAn inline Web Application Firewall filtering Cross-Site Scripting attempts
- CA stateful firewall operating as a preventive network control to block malicious port scans
- DAn inline intrusion prevention rule deployed to mitigate operating system buffer overflow exploits
Cevap
A honeypot deployed as a deception mechanism to detect unauthorized internal access
A honeypot is a security control designed to act as a decoy to lure potential attackers or unauthorized users. Because a honeypot has no legitimate business purpose or real production traffic, any interaction or connection attempt made to it generates a high-confidence alert for security analysts.
Adım Adım Çözüm
Anahtar Kavram
Honeypots and Deception Technologies in Network Security Monitoring