Which of the following would most likely be deployed to obtain and analyze attacker activity and techniques?
Choose an answer
Tap an option to check your answer.
Correct answer: Honeypot.
Why this is the answer
A honeypot is a security mechanism designed to lure attackers by appearing to be a legitimate, vulnerable system. Its primary purpose is to observe, analyze, and collect information about attacker tactics, techniques, and procedures (TTPs) without risking actual production systems. This allows organizations to understand threats better and improve their defenses. A firewall controls network traffic based on predefined rules but doesn't actively attract or analyze attacker behavior. An Intrusion Detection System (IDS) monitors network or system activities for malicious behavior and alerts administrators, but it doesn't serve as a decoy to gather intelligence. A Layer 3 switch operates at the network layer, forwarding traffic between different subnets, and is a networking device, not a security intelligence gathering tool.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed