Courseiva
Security Operations →easyMultiple Choice

CAS-004 Security Operations Practice Question

An organization deploys honeypots to detect attackers. Which type of deception technology is being used?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Honeypots

Honeypots are decoy systems designed to lure attackers and detect unauthorized activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Honeytokens

    Why it's wrong here

    Honeytokens are planted data artefacts such as fake credentials or files that trigger alerts when accessed, not decoy systems. They are tempting because they are a deception technique that detects attacker activity, and would be correct if the scenario described embedding fake records or API keys rather than deploying honeypot hosts.

  • ✗

    Bait networks

    Why it's wrong here

    Bait networks are fabricated network segments or credentials used to lure attackers, not the honeypot systems themselves that the stem describes. They are tempting because they also fall under deception technology and detect lateral movement, and would be correct if the scenario involved fake network topology or planted credentials rather than deployed honeypot hosts.

  • ✓

    Honeypots

    Why this is correct

    Honeypots are decoy systems that deliberately expose fake vulnerabilities to lure attackers, logging their activity without risking real assets. This directly satisfies the stem's requirement for deception technology, since honeypots constitute the deception mechanism itself rather than a detection or prevention control layered alongside it.

  • ✗

    Honeynets

    Why it's wrong here

    A honeynet is a network of multiple honeypot hosts, whereas the stem describes deploying honeypots, a single decoy system category. Honeynets are tempting because they capture richer attacker behaviour across several interconnected decoys, and would be correct if the scenario specified a whole decoy network rather than individual honeypots.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.