Which of the following methods can be used to detect attackers who have successfully infiltrated a network? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Honeypots, DNS sinkhole.
Why this is the answer
Honeypots are decoy systems designed to attract and trap attackers, allowing security teams to observe their tactics, techniques, and procedures (TTPs) without risking actual production systems. This provides valuable intelligence on post-infiltration activities. A DNS sinkhole redirects malicious DNS requests (e.g., to command-and-control servers) to a controlled server, preventing communication with actual attacker infrastructure and logging the attempts. This helps identify compromised internal systems that are trying to connect to known malicious domains. Tokenization and data obfuscation are data protection techniques, not detection methods for active intrusions. CI/CD (Continuous Integration/Continuous Deployment) is a software development practice. Threat modeling is a proactive design-phase security analysis technique, not a post-infiltration detection method.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed