Courseiva
mediumMultiple Choice

ISC2 CC Practice Question: A company deploys a new intrusion detection…

A company deploys a new intrusion detection system (IDS) on the internal network. Which of the following best describes the primary purpose of this system?

⚠ Common exam trap

ISC2 often tests the distinction between IDS and IPS, where candidates mistakenly assume an IDS can block traffic because they conflate detection with prevention.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Detect and alert on potential security incidents.

An intrusion detection system (IDS) is a passive monitoring technology that analyzes network traffic or system activity for signs of malicious behavior or policy violations. Unlike an intrusion prevention system (IPS), an IDS does not take inline action to block traffic; its primary purpose is to detect suspicious activity and generate alerts for security personnel to investigate and respond.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Block malicious traffic in real time.

    Why it's wrong here

    An IDS detects and alerts on malicious activity; blocking traffic in real time is the function of an intrusion prevention system (IPS) placed inline. It is tempting because detection often precedes response, and an IPS would be correct where inline enforcement is required.

  • ✓

    Detect and alert on potential security incidents.

    Why this is correct

    An IDS passively inspects mirrored traffic and generates alerts on suspicious patterns, satisfying the detection requirement without sitting inline. It identifies and notifies; it does not block, which distinguishes it from an IPS. Prevention and quarantine fall outside its primary purpose.

  • ✗

    Encrypt sensitive data at rest.

    Why it's wrong here

    Encryption at rest is provided by disk, database or file-level encryption, not by an IDS, which inspects network traffic for signs of intrusion. It is tempting because both are security controls, and encryption would be correct for protecting stored data confidentiality.

  • ✗

    Prevent unauthorized access to the network.

    Why it's wrong here

    Preventing unauthorised access is the role of firewalls, access control and authentication; an IDS passively monitors and alerts rather than enforcing admission. It is tempting because IDS alerts support access security, and a firewall would be correct where traffic must be blocked.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.