Courseiva
mediumMultiple Select

APT Detection: Honeypots and Threat Intelligence Feeds

A SOC wants to improve detection of advanced persistent threats (APTs) that evade traditional signature-based tools. Which TWO approaches are most effective? (Select exactly 2.)

Quick Answer

The answer is integrating external threat intelligence feeds into the SIEM and deploying deception technology such as honeypots. These two approaches are most effective for APT detection because they target the unknown and stealthy nature of advanced persistent threats. Honeypots act as decoy systems that lure attackers, revealing their tactics, techniques, and procedures (TTPs) without risking production assets, while threat intelligence feeds provide real-time indicators of compromise (IOCs) and adversary behavior patterns that signature-based tools miss. On the CompTIA SecurityX CAS-004 exam, this question tests your understanding of proactive detection methods beyond traditional antivirus or log management—a common trap is confusing increased log storage (option B) with improved detection capability. Remember the mnemonic “HIT the APT”: Honeypots and Intelligence feeds together catch what signatures cannot.

⚠ Common exam trap

The trap is selecting options that improve general security posture (more analysts, longer retention, fewer false positives) instead of the two approaches specifically designed to detect evasive APTs: deception and threat intelligence integration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy honeypots and deception technology

Option D is correct because honeypots and deception technology create decoy assets and fake credentials that have no legitimate production purpose, so any interaction with them is high-fidelity evidence of adversary reconnaissance or lateral movement, which is exactly the kind of stealthy, low-signature behavior APTs exhibit. Option E is correct because integrating external threat intelligence feeds (e.g., STIX/TAXII indicators such as malicious IPs, domains, and file hashes) into the SIEM enriches correlation rules and enables detection of known APT infrastructure and TTPs that signature-based tools miss. Option A is not the best fit because lowering SIEM false positives improves analyst efficiency and alert quality but does not by itself add new detection capability against evasive APTs. Option B is not the best fit because extending log retention to 12 months supports retroactive hunting and forensic timelines but does not directly improve detection of threats that evade signatures. Option C is not the best fit because hiring more analysts adds human capacity for triage and hunting but is not a technical detection approach and scales poorly against advanced threats without supporting tooling.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reduce the false positive rate of the SIEM

    Why it's wrong here

    Tuning the SIEM to reduce false positives narrows detection logic, which suppresses the low-fidelity signals APTs rely on and worsens blind spots. False-positive reduction suits mature environments drowning in noisy alerts, not hunting adversaries whose subtle indicators resemble benign activity.

  • ✗

    Increase log retention period to 12 months

    Why it's wrong here

    Extending retention preserves evidence for retrospective hunting but adds no new detection capability; APTs still evade signature matching during the window. Long retention suits forensic investigation and compliance auditing after an incident, not proactive identification of novel adversary techniques.

  • ✗

    Hire additional security analysts

    Why it's wrong here

    Additional analysts increase triage capacity but apply the same signature-based tooling, so novel APT techniques remain undetected regardless of headcount. Staffing suits alert-volume backlogs and 24/7 coverage gaps, not closing the detection gap that behavioural analytics and threat hunting address.

  • ✓

    Deploy honeypots and deception technology

    Why this is correct

    Honeypots and deception technology present fake assets with no legitimate traffic, so any interaction is inherently suspicious. This exposes APT reconnaissance and lateral movement that signature-based tools miss, satisfying the stem's requirement to detect evasive threats.

  • ✓

    Integrate external threat intelligence feeds into the SIEM

    Why this is correct

    External threat intelligence feeds supply indicators of compromise and adversary context, letting the SIEM match observed activity against known APT infrastructure and tactics. This enriches detection beyond signatures, addressing the stem's need to catch threats that evade traditional tools.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CAS-005

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which THREE of the following are effective techniques for detecting advanced persistent threats (APTs) within a network? (Select exactly 3.)

hard
  • A.Using signature-based intrusion detection systems (IDS) to match known attack patterns.
  • ✓ B.Conducting behavioral analysis of endpoint and network activity to detect unusual patterns.
  • ✓ C.Integrating threat intelligence feeds to correlate indicators of compromise (IOCs) with internal logs.
  • ✓ D.Implementing anomaly-based network traffic analysis to identify deviations from baseline behavior.
  • E.Deploying honeypots to attract and analyze attacker behavior.

Why B: Option B is correct because behavioral analysis of endpoint and network activity detects APTs by identifying deviations from normal user and process behavior, which is essential since APTs often use stealthy, novel techniques that evade static signatures. Option C is correct because integrating threat intelligence feeds allows correlation of known indicators of compromise (IOCs) such as malicious IPs, domains, and file hashes with internal logs, helping to surface APT-related activity that matches external intelligence. Option D is correct because anomaly-based network traffic analysis establishes a baseline and flags deviations, which can reveal command-and-control traffic, lateral movement, or data exfiltration typical of APTs. Option A is not among the correct answers because signature-based IDS only matches known attack patterns and is largely ineffective against APTs that use zero-days, polymorphic malware, and living-off-the-land techniques. Option E is not among the correct answers because while honeypots can provide useful deception and attacker behavior insights, they are not a primary or reliable technique for detecting APTs across an entire network and are better suited as a complementary deception control.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.