A school-district SOC is choosing complementary host and deception controls beyond the firewall. Which mix is used appropriately?
Select an answer to reveal the explanation.
Short Explanation
Think toolbox, not one magic gadget: allow or deny lists, sandbox the weird attachments, maybe a honeypot for early warning, and keep anti-malware on. Parking payroll in a honeynet or grabbing random freeware is the wrong complementary mix.
Full Explanation
Complementary detection and prevention measures include allowlisting and blocklisting, sandboxing, honeypots or honeynets used carefully for detection, and anti-malware. These controls reinforce perimeter and host defenses when operated with clear purpose and isolation. Misusing deception environments for production workloads or abandoning preventative listing and malware defenses weakens the stack.