A Chief Security Officer signs off on a request to allow inbound SMB and RDP from the internet to a single VLAN. Which of the following is the most likely explanation for this activity?
A.
The company built a new file-sharing site.
B.
The organization is preparing for a penetration test.
C.
The security team is integrating with an SASE platform.
Allowing risky protocols like SMB and RDP from the internet to a controlled VLAN is commonly done to create a honeynet, a deliberately vulnerable network environment used to attract attackers and study their behaviors without risking production systems.
Building a file-sharing site (A) or preparing for a pentest (B) typically wouldn ' t require exposing SMB and RDP broadly. SASE integration (C) focuses on cloud security access and doesn ' t involve opening such protocols indiscriminately.
Honeynets are described as a deception technology in the Security Architecture domain【6:Chapter 9†CompTIA Security+ Study Guide】.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit