CAS-004 Security Operations Practice Question
A security architect is designing deception technologies to detect and delay attackers. Which TWO of the following are examples of deception technologies that can be deployed? Select TWO.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Honeytokens
Honeytokens (A) are deception artifacts such as fake credentials, files, or database records that have no legitimate use, so any access or use of them is a high-fidelity indicator of malicious activity and can trigger alerts while wasting attacker time. Honeypots (B) are decoy systems or services deliberately exposed to attract and observe attackers, allowing defenders to detect intrusions, collect TTPs, and delay or divert adversaries from real assets. SIEM (C) is a log aggregation, correlation, and alerting platform, not a deception mechanism, so it does not itself lure or deceive attackers. A vulnerability scanner (D) is an assessment tool that identifies weaknesses in systems and does not create decoys or false targets. An IPS (E) is a preventive control that detects and blocks malicious traffic inline, but it is not a deception technology because it does not present fake assets or bait to attackers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Honeytokens
Why this is correct
Honeytokens are decoy credentials, files or records seeded across systems; any access triggers an alert, since legitimate users have no reason to touch them. This satisfies the stem's detection requirement, giving high-fidelity, low-false-positive signals of attacker reconnaissance or lateral movement without delaying normal business activity.
- ✓
Honeypots
Why this is correct
Honeypots are decoy systems that mimic genuine production assets, luring attackers into interacting with them. Any engagement generates high-fidelity alerts with near-zero false positives, satisfying the stem's requirement to detect attackers while consuming their time and delaying lateral movement across the estate.
- ✗
Security Information and Event Management (SIEM)
Why it's wrong here
A SIEM aggregates and correlates log events for detection and alerting; it deploys no decoy or trap, so it cannot deceive or delay an adversary. It is tempting because it detects malicious activity, yet SIEM is correct when centralised monitoring and correlation are required.
- ✗
Vulnerability scanner
Why it's wrong here
A vulnerability scanner audits hosts for known weaknesses; it neither lures attackers nor delays them, so it provides no deception. It is tempting because it supports security assessment, but scanning is the right answer when the requirement is identifying exposures rather than deploying decoys.
- ✗
Intrusion Prevention System (IPS)
Why it's wrong here
An IPS actively blocks detected traffic inline; it detects and prevents but deploys no decoy assets, so it cannot deceive or delay an attacker. It is tempting because it is a defensive control, yet IPS is the correct choice for inline threat prevention, not deception.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.