Courseiva
Security Operations →easyMultiple Choice

CAS-004 Security Operations Practice Question

An organization wants to deploy a technology that lures attackers into a controlled environment to observe their tactics, techniques, and procedures (TTPs). Which deception technology should the organization implement?

⚠ Common exam trap

CAS-005 often tests the confusion between honeypots and honeytokens—candidates may pick honeytoken thinking it 'lures' attackers, but honeytokens are passive tripwires, not interactive decoy environments.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Honeypot

A honeypot is a decoy system intentionally designed to attract and deceive attackers, allowing defenders to observe their tactics, techniques, and procedures (TTPs) in a controlled environment. It mimics vulnerable services or entire networks, and any interaction with it is inherently suspicious, providing high-fidelity threat intelligence with minimal false positives. This matches the requirement to 'lure attackers into a controlled environment' for TTP observation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Honeytoken

    Why it's wrong here

    A honeytoken is a single fake credential or file that triggers an alert when touched; it offers no environment for sustained TTP observation. It tempts because it is deception, but luring attackers into an interactive controlled space requires a honeypot, not a token.

  • ✗

    EDR

    Why it's wrong here

    EDR monitors and responds on real endpoints; it neither lures nor hosts attackers, so no controlled observation environment exists. It tempts because EDR records attacker behaviour, but that telemetry comes from production hosts, whereas deception requires decoy systems that invite intrusion.

  • ✓

    Honeypot

    Why this is correct

    A honeypot is a decoy system deliberately exposed to attract attackers, letting defenders observe their tactics, techniques and procedures within a controlled, monitored environment. It satisfies the requirement to lure adversaries and record their behaviour without risking production assets.

  • ✗

    SIEM

    Why it's wrong here

    SIEM aggregates and correlates log events for detection and investigation; it does not create decoy assets or lure attackers into interacting with them. It is tempting because SIEM underpins detection engineering and threat hunting, and would be the right choice when the requirement is centralised log analysis, alerting or compliance reporting rather than deception.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.