Courseiva
Network Security →mediumMultiple Select

ISC2 CC Network Security Practice Question

A security analyst wants to detect and analyze attacker behavior by deploying a decoy system. Which three characteristics apply to a honeypot? (Choose THREE.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It is a decoy system to attract attackers

Honeypots are decoy systems designed to attract attackers, provide early warning, and allow analysis of attacker techniques. They do not contain real production data and are not used for legitimate traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    It is a decoy system to attract attackers

    Why this is correct

    A honeypot is deliberately deployed as a decoy system to attract attackers, luring them away from production assets while recording their behaviour. This satisfies the analyst's goal of detecting and analysing attacker behaviour through a decoy.

  • ✓

    It provides early warning of attacks

    Why this is correct

    A honeypot has no production role, so any interaction with it is inherently suspicious. That lets it flag reconnaissance or exploitation attempts the moment they occur, delivering early warning of attacks before real assets are touched, satisfying the analyst's need to detect attacker behaviour.

  • ✗

    It contains sensitive production data

    Why it's wrong here

    Honeypots hold fabricated or non-sensitive data, because a compromised decoy must not expose real assets. The option tempts because production systems legitimately store sensitive data, and a convincing decoy may mimic such content superficially. Placing genuine production data on a honeypot would create risk without detection benefit, defeating its purpose.

  • ✗

    It is used for legitimate network traffic

    Why it's wrong here

    Honeypots deliberately carry no legitimate traffic; any interaction is by definition suspicious, which is what makes them useful detection decoys. The option is tempting because production systems exist precisely to serve legitimate users, so the phrase sounds like normal infrastructure. A honeypot's value comes from isolation, not from handling real business flows.

  • ✓

    It allows analysis of attacker tactics

    Why this is correct

    Because a honeypot is instrumented and isolated, every command, payload and lateral-movement attempt is captured for study. This directly satisfies the requirement to analyse attacker behaviour, revealing the tools, techniques and procedures used rather than merely blocking traffic.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.