N10-009 exam dumps

N10-009 practice question 253 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 253

Single answerDeception technologies: Honeypot, Honeynet

A security administrator wants to study how attackers probe the company's public-facing services without putting production systems at additional risk. The administrator proposes deploying several decoy systems that mimic vulnerable web and file services, placing them in an isolated segment with tightly controlled outbound access and extensive logging. Which solution best meets this goal?

  1. A

    Deploy a honeynet containing multiple honeypots in an isolated network segment

  2. B

    Deploy a load balancer in front of the production servers to distribute attacker traffic

  3. C

    Deploy a VPN concentrator so only authenticated users can reach public-facing services

  4. D

    Deploy a jump server for administrators to manage the production environment

Show answer and explanation

Correct answer: A

Explanation

The best answer is to deploy a honeynet containing multiple honeypots in an isolated network segment. A honeypot is a decoy host or service intended to attract attackers and generate alerts or intelligence when accessed. A honeynet extends this concept by using multiple decoy systems to simulate a realistic environment, which is especially useful when defenders want to study attacker techniques across more than one service. In practice, deception systems should be segmented from production networks, heavily monitored, and configured with restricted outbound access to reduce the risk that a compromised decoy could be used to attack other systems. This aligns with common security architecture guidance from organizations such as NIST, which emphasizes network segmentation, logging, and containment for higher-risk systems and research environments.

  • A. Correct.

    Correct. A honeynet is a network of honeypots designed to attract, detect, and study attacker behavior. In this scenario, the requirement is for several decoy systems that simulate services, are isolated from production, and provide detailed monitoring. Those characteristics align directly with a honeynet deployment. Best practice is to isolate deception systems and restrict outbound connectivity so they can gather intelligence without becoming a launch point for attacks against other systems.

  • B. Incorrect.

    Incorrect. A load balancer improves availability and can distribute legitimate or malicious traffic across backend servers, but it is not a deception technology. It does not create decoy targets for observing attacker behavior, and it would not meet the goal of safely studying probes against imitation services.

  • C. Incorrect.

    Incorrect. A VPN concentrator controls remote access by requiring authenticated tunnels, which can reduce exposure of internal resources. However, it does not function as a decoy environment and would not help the administrator observe how attackers interact with fake services. Someone might choose this because it is a security control for remote access, but it is preventive rather than deceptive.

  • D. Incorrect.

    Incorrect. A jump server provides a controlled administrative access point into an environment. While it supports secure management practices, it is not intended to lure attackers or gather intelligence on probing activity. This option may seem plausible because it involves segmentation and control, but it does not satisfy the deception requirement.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam