Which Fortinet product is specifically designed to deploy decoys and lures to detect lateral movement and early-stage attacks inside the network?
FortiDeceptor deploys decoys and lures across network segments, mimicking real assets to attract attackers. Any interaction with these decoys generates high-fidelity alerts on lateral movement and early-stage intrusion attempts, satisfying the requirement for deception-based threat detection rather than perimeter or signature-based defence.
Why this answer
FortiDeceptor is specifically designed to deploy decoys and lures that mimic real assets (e.g., servers, endpoints, IoT devices) to attract and detect lateral movement and early-stage attacks inside the network. It uses deception technology to create a realistic attack surface, triggering alerts when an attacker interacts with a decoy, without relying on signatures or behavioral analysis.
Exam trap
The trap here is that candidates often confuse FortiDeceptor with FortiSandbox or FortiEDR because all three are part of the Advanced Threat Protection portfolio, but only FortiDeceptor focuses on deception-based detection of lateral movement rather than file analysis or endpoint response.
How to eliminate wrong answers
Option A is wrong because FortiSandbox is a threat analysis and sandboxing solution that detonates files and URLs in a controlled environment to detect unknown malware, not a deception-based tool for deploying decoys and lures. Option B is wrong because FortiEDR is an endpoint detection and response solution that monitors and responds to threats on endpoints using behavioral analysis and machine learning, not a decoy deployment system. Option D is wrong because FortiClient is a lightweight endpoint agent for VPN, web filtering, and basic antivirus, lacking the dedicated deception capabilities to deploy decoys and lures for lateral movement detection.