ワシントン州シアトル。倫理ハッカーのミア・チェンは、パシフィック・トラスト銀行に雇われ、顧客の機密性の高い金融データを保管する企業ネットワークのセキュリティテストを行う。侵入テスト中、ミアは徹底的な偵察を行い、重要な取引記録データベースをホストしていると思われるサーバーを標的とする。サーバーとやり取りするうちに、クエリには迅速に応答する一方で、予期しないプロトコル応答など、実稼働システムの動作とは矛盾すると思われるエラーメッセージが時折返されることに気づいた。
このサーバーが自分の行動を監視するためのおとりである可能性を疑ったミアは、システムがハニーポットである可能性を明らかにする不一致を検出する技術を適用します。
Pacific Trust Bank のサーバーがハニーポットであるかどうかを判断するために、Mia が使用している可能性が高い手法はどれですか。
正解:C
Fingerprinting the running service is the most appropriate technique because the strongest indicator in the scenario is inconsistent protocol behavior and error responses that do not match a legitimate production database service. In CEH reconnaissance guidance, honeypots and decoy systems often emulate common services but may implement only partial protocol stacks or simplified responses. This can lead to anomalies such as incorrect banner strings, malformed or generic error messages, unsupported command handling, unusual protocol negotiation, or responses that do not align with the claimed software version. By fingerprinting, Mia compares observed behavior against expected behavior for the genuine service, including version-specific quirks, command sets, response codes, and timing patterns for particular requests.
In practice, service fingerprinting involves interacting with the service using legitimate and edge-case requests, validating banners and headers, and correlating results with known signatures from real implementations. If the server claims to be a specific database or application service but reacts in ways that real deployments would not, it suggests emulation, instrumentation, or deception typical of honeypots designed to log attacker activity.
Analyzing response time can help, because some honeypots respond too quickly or with uniform timing, but timing alone is less definitive than protocol inconsistencies. MAC address analysis is not reliable for identifying honeypots and is often not visible beyond the local segment. Analyzing system configuration and metadata usually requires deeper access than reconnaissance and is not the primary method when the clue is protocol-level mismatch. Therefore, fingerprinting the running service best fits the observed symptoms.