An EDR alert shows an unusual RDP session from a workstation to a server using a valid domain service account. The SOC wants to confirm whether stolen credentials are being reused for lateral movement without exposing production accounts to risk. Which action best supports that goal?
Select an answer to reveal the explanation.
Short Explanation
Think of it like a tripwire: a honey token is a credential nobody legitimately uses, so if it authenticates, something is wrong. You get proof of stolen-credential reuse without letting attackers touch a real account. The trap is confusing detection on real accounts with confirmation of abuse.
Full Explanation
A honey token credential is a deliberately unused identity or secret that generates high-fidelity alerts when used. Because it has no legitimate workload, successful authentication is direct evidence that an attacker has obtained and is replaying credentials. In a hybrid SOC, an analyst can create a decoy service account in Active Directory, exclude it from normal logon and service paths, and forward authentication events to the SIEM. If lateral movement occurs with that credential, the SOC confirms credential abuse while keeping real service accounts out of the attacker’s reach. Privileged account monitoring can detect risky use of real accounts, but it does not create a guaranteed no-false-positive trigger and may still expose production identities. Rotating all service-account passwords reduces the value of stolen secrets, yet it provides no telemetry proving that those secrets were used. Baseline normal RDP authentication patterns helps identify anomalous sessions, but it cannot distinguish stolen-credential reuse from legitimate but unusual access. Exam caveat: CompTIA may describe this as a honey token, canary token, decoy account, or deception credential; choose the option that creates telemetry only when the decoy is used. Operational check: create a service account with no assigned services, place it in a monitored authentication group, and alert on any logon.