Which of the following describes the primary goal of using a 'Honeytoken' in an environment to mitigate malicious code and insider threats?
The purpose of a honeytoken is to act as a detection mechanism. By creating a resource that serves no business purpose, any interaction with it serves as a clear indicator of malicious intent, allowing security teams to respond immediately to threats that have evaded other detection controls.
Why this answer
Honeytokens are fake credentials, files, or data entries planted in a system to act as a tripwire. Because no legitimate user or process should ever access these items, any attempt to use or read them provides a high-fidelity alert of malicious activity. This strategy is highly effective for detecting lateral movement, data exfiltration attempts, or credential harvesting by malware that is already inside the perimeter and searching for targets.
Exam trap
Candidates often mistake honeytokens for 'prevention' tools. They are strictly detection mechanisms; they do not block or stop an attacker from accessing the actual system.