QuestionQ54

Security Operations

During an adversarial simulation exercise, an external team was able to gain access to sensitive information and systems without the organization detecting this activity. Which of the following mitigation strategies should the organization use to best resolve the findings?

Explanation

Decoy accounts and documents are honeytokens: fake credentials or files planted throughout the environment that have no legitimate reason to be touched, so any interaction with them is a high-fidelity signal of intrusion. This directly closes the detection gap the exercise exposed. A honeypot or honeynet mainly characterizes attacker behavior on an isolated system an adversary must first find and target, and attack simulators test control coverage rather than catch a live intruder already inside the environment.

Community Discussion

No comments yet. Be the first to start the discussion!