Courseiva
Security Operations →hardMultiple Choice

CAS-004 Security Operations Practice Question

A security operations team has deployed a deception platform consisting of several Windows and Linux honeypots on a dedicated VLAN. After two weeks, the team notices the honeypots generate a high volume of connection attempts originating from internal vulnerability scanners, asset discovery tools, and backup agents, drowning out any genuine adversary activity. Which of the following is the BEST course of action to preserve the fidelity of the deception environment?

⚠ Common exam trap

The trap here is treating honeypot noise as a reason to abandon or isolate the deception layer, rather than tuning suppression for known benign sources while keeping the environment live.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Tune the deception platform to suppress alerts for known scanner, discovery, and backup agent signatures and source addresses, while forwarding all other honeypot interactions to the SIEM.

Deception environments lose value when benign, authorized traffic overwhelms the alerts they produce. The practical fix is to baseline and suppress the deterministic signatures and source addresses of sanctioned tools such as vulnerability scanners, asset discovery engines, and backup agents, while continuing to forward every other honeypot interaction to the SIEM. This preserves the honeypot's high-fidelity detection role without discarding it or exposing production networks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Place the honeypots behind a firewall rule that permits only traffic from external IP address ranges.

    Why it's wrong here

    Restricting honeypot access to external ranges would block the very internal lateral-movement and reconnaissance activity that deception is meant to catch. An adversary who has already established a foothold inside the network typically pivots from internal hosts, so this control would suppress meaningful telemetry while leaving east-west threats undetected. It also does not address the noise already generated by internal scanners and backup agents.

  • ✗

    Decommission the honeypots and replace them with host-based intrusion detection agents installed on production servers.

    Why it's wrong here

    Host-based agents on production systems monitor real workloads rather than decoys, so they cannot generate the low-false-positive, high-fidelity alerts that a honeypot interaction provides. Removing the deception layer eliminates the early-warning capability entirely instead of fixing an alert-tuning problem. This is a disproportionate response to noise that can be resolved through suppression rules and source filtering.

  • ✗

    Move the honeypots to the same VLAN as production servers so that legitimate administrative traffic blends in with adversary activity.

    Why it's wrong here

    Co-locating honeypots with production systems increases the risk of compromise spreading from the decoy to real assets and still does not reduce scanner or backup noise. Legitimate administrative traffic would in fact generate more benign hits, worsening the fidelity problem. Segmentation onto a dedicated VLAN is a deliberate design choice that supports containment and clean telemetry and should be retained.

  • ✓

    Tune the deception platform to suppress alerts for known scanner, discovery, and backup agent signatures and source addresses, while forwarding all other honeypot interactions to the SIEM.

    Why this is correct

    Deception fidelity depends on distinguishing authorized tooling from adversary behavior. By fingerprinting the deterministic traffic patterns and source addresses of sanctioned scanners and backup agents and suppressing only those events, the team removes expected noise without blinding the environment to novel or anomalous connections. All other honeypot interactions remain high-signal indicators worth forwarding to the SIEM for correlation and triage.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.