CAS-004 Security Operations Practice Question
An organization deploys honeypots to detect attackers. Which type of deception technology is being used?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Honeypots
Honeypots are decoy systems designed to lure attackers and detect unauthorized activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Honeytokens
Why it's wrong here
Honeytokens are planted data artefacts such as fake credentials or files that trigger alerts when accessed, not decoy systems. They are tempting because they are a deception technique that detects attacker activity, and would be correct if the scenario described embedding fake records or API keys rather than deploying honeypot hosts.
- ✗
Bait networks
Why it's wrong here
Bait networks are fabricated network segments or credentials used to lure attackers, not the honeypot systems themselves that the stem describes. They are tempting because they also fall under deception technology and detect lateral movement, and would be correct if the scenario involved fake network topology or planted credentials rather than deployed honeypot hosts.
- ✓
Honeypots
Why this is correct
Honeypots are decoy systems that deliberately expose fake vulnerabilities to lure attackers, logging their activity without risking real assets. This directly satisfies the stem's requirement for deception technology, since honeypots constitute the deception mechanism itself rather than a detection or prevention control layered alongside it.
- ✗
Honeynets
Why it's wrong here
A honeynet is a network of multiple honeypot hosts, whereas the stem describes deploying honeypots, a single decoy system category. Honeynets are tempting because they capture richer attacker behaviour across several interconnected decoys, and would be correct if the scenario specified a whole decoy network rather than individual honeypots.
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.