PrepAway - Latest Free Exam Questions & Answers

Which of the following should an administrator implement to research current attack methodologies?

Which of the following should an administrator implement to research current attack methodologies?

PrepAway - Latest Free Exam Questions & Answers

A.
Design reviews

B.
Honeypot

C.
Vulnerability scanner

D.
Code reviews

Explanation:
A honeypot is a system whose purpose it is to be attacked. An administrator can watch and study the
attack to research current attack methodologies.
According to the Wepopedia.com, a Honeypot luring a hacker into a system has several main purposes:
The administrator can watch the hacker exploit the vulnerabilities of the system, thereby learning where
the system has weaknesses that need to be redesigned.
The hacker can be caught and stopped while trying to obtain root access to the system.
By studying the activities of hackers, designers can better create more secure systems that are potentially
invulnerable to future hackers.
There are two main types of honeypots:
Production – A production honeypot is one used within an organization’s environment to help mitigate
risk.
Research – A research honeypot add value to research in computer security by providing a platform to
study the threat.
Incorrect Answers:
A: Reviewing the design of a system would not help to determine current attack methodologies. You
would use a honeypot to determine current attack methodologies. You might then have a design review
to counteract the threats.
C: A vulnerability scanner scans a system or network for known vulnerabilities. It is not used to determine
new attack methodologies.D: Reviewing the code of an application would not help to determine current attack methodologies. You
would use a honeypot to determine current attack methodologies. You might then have a code review to
counteract the threats.

https://ethics.csc.ncsu.edu/abuse/hacking/honeypots/study.php


Leave a Reply