Courseiva
Security Operations →mediumMultiple Select

CAS-004 Security Operations Practice Question

A security architect is designing deception technologies to detect and delay attackers. Which TWO of the following are examples of deception technologies that can be deployed? Select TWO.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Honeytokens

Honeytokens (A) are deception artifacts such as fake credentials, files, or database records that have no legitimate use, so any access or use of them is a high-fidelity indicator of malicious activity and can trigger alerts while wasting attacker time. Honeypots (B) are decoy systems or services deliberately exposed to attract and observe attackers, allowing defenders to detect intrusions, collect TTPs, and delay or divert adversaries from real assets. SIEM (C) is a log aggregation, correlation, and alerting platform, not a deception mechanism, so it does not itself lure or deceive attackers. A vulnerability scanner (D) is an assessment tool that identifies weaknesses in systems and does not create decoys or false targets. An IPS (E) is a preventive control that detects and blocks malicious traffic inline, but it is not a deception technology because it does not present fake assets or bait to attackers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Honeytokens

    Why this is correct

    Honeytokens are decoy credentials, files or records seeded across systems; any access triggers an alert, since legitimate users have no reason to touch them. This satisfies the stem's detection requirement, giving high-fidelity, low-false-positive signals of attacker reconnaissance or lateral movement without delaying normal business activity.

  • ✓

    Honeypots

    Why this is correct

    Honeypots are decoy systems that mimic genuine production assets, luring attackers into interacting with them. Any engagement generates high-fidelity alerts with near-zero false positives, satisfying the stem's requirement to detect attackers while consuming their time and delaying lateral movement across the estate.

  • ✗

    Security Information and Event Management (SIEM)

    Why it's wrong here

    A SIEM aggregates and correlates log events for detection and alerting; it deploys no decoy or trap, so it cannot deceive or delay an adversary. It is tempting because it detects malicious activity, yet SIEM is correct when centralised monitoring and correlation are required.

  • ✗

    Vulnerability scanner

    Why it's wrong here

    A vulnerability scanner audits hosts for known weaknesses; it neither lures attackers nor delays them, so it provides no deception. It is tempting because it supports security assessment, but scanning is the right answer when the requirement is identifying exposures rather than deploying decoys.

  • ✗

    Intrusion Prevention System (IPS)

    Why it's wrong here

    An IPS actively blocks detected traffic inline; it detects and prevents but deploys no decoy assets, so it cannot deceive or delay an attacker. It is tempting because it is a defensive control, yet IPS is the correct choice for inline threat prevention, not deception.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.