ISC2 CC Network Security Practice Question
A hospital's security team wants to detect when an attacker is probing its internal network for open ports, but the team must not block legitimate clinical traffic because doing so could interrupt patient care. The team decides to deploy a solution that only alerts on suspicious activity. Which type of solution best matches this requirement?
⚠ Common exam trap
The trap here is assuming that any intrusion detection tool will also block attacks, when detection-only monitoring is specifically required to avoid disrupting clinical traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A network-based intrusion detection system (NIDS)
The requirement is detection without disruption, which points to a passive monitoring technology. A network-based intrusion detection system observes copies of traffic and raises alerts on suspicious activity such as port scanning, but it does not sit inline to block. Prevention systems, web application firewalls, and stateful firewalls either block traffic or focus on the wrong layer for this internal reconnaissance scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A network-based intrusion prevention system (NIPS)
Why it's wrong here
A NIPS sits inline and can drop or reset malicious traffic, which could block legitimate clinical traffic if a rule misfires or a scan resembles normal activity. The scenario explicitly states that blocking must be avoided. Although a NIPS detects probing, its preventive action violates the stated constraint, making it unsuitable here.
- ✗
A stateful packet-filtering firewall
Why it's wrong here
A stateful firewall enforces access control based on connection state and can block traffic, but it is not designed to alert on reconnaissance patterns like port scans across the internal network. It also may deny traffic, which conflicts with the requirement not to interrupt clinical communications. It lacks the detection and alerting focus needed here.
- ✓
A network-based intrusion detection system (NIDS)
Why this is correct
A NIDS monitors network traffic and generates alerts for suspicious patterns such as port scans without actively blocking traffic. Because it is passive, it will not interrupt clinical communications even if it flags legitimate activity. This matches the requirement to detect probing while avoiding any disruption to patient care.
- ✗
A web application firewall (WAF)
Why it's wrong here
A WAF protects web applications by inspecting HTTP and HTTPS requests, typically deployed in front of web servers. It does not monitor general internal network traffic for port scanning across many hosts and services. Its focus on application-layer web traffic means it would miss the broad network reconnaissance described in the scenario.
Go deeper
Related to this question
Learn chapter
Secure Network Architecture and Design
Key term
Detection
Detection is the process of identifying potential security incidents or anomalies by analyzing system data, logs, and network traffic.
Key term
Intrusion Detection System
An Intrusion Detection System (IDS) is a security tool that monitors network traffic or system activities for malicious actions or policy violations and sends alerts to administrators.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.