What is the security purpose of deploying a honeypot inside an enterprise network (internal honeypot)?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because an internal honeypot is a fake system with no legitimate purpose; any network connection to it indicates either a misconfigured system, a scanning attacker, or lateral movement activity — making it a high-fidelity detection mechanism. A is wrong because internet-facing honeypots study external attackers; internal honeypots are designed to detect internal threats.
Full explanation below image
Full Explanation
B is correct because an internal honeypot is a fake system with no legitimate purpose; any network connection to it indicates either a misconfigured system, a scanning attacker, or lateral movement activity — making it a high-fidelity detection mechanism. A is wrong because internet-facing honeypots study external attackers; internal honeypots are designed to detect internal threats. C is wrong because honeypots are low-interaction detection tools, not DDoS mitigation systems. D is wrong because IDS testing is done with lab environments or dedicated tools, not production honeypots.