Courseiva
Network Security →hardMultiple Choice

ISC2 CC Network Security Practice Question

A security administrator is configuring a network tap to monitor traffic between two switches. The administrator needs to ensure that the monitoring device receives a copy of all traffic, including packets that might be dropped due to errors. Which type of tap should be used?

⚠ Common exam trap

Watch out — candidates often confuse active and passive taps; active taps regenerate signals and may drop errors, while passive taps provide a true copy of all traffic, including errors.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Passive tap

A passive tap splits the signal without regeneration, ensuring that all traffic, including errored packets, is copied to the monitoring port. Active and regenerating taps may filter or drop errored frames. For complete traffic capture, a passive tap is the correct choice.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Passive tap

    Why this is correct

    A passive tap, also known as a break-out tap, splits the signal optically or electrically without regenerating it. It forwards all traffic, including errored packets, because it does not interpret or filter the data. This makes it ideal for capturing a complete copy of traffic for analysis, including frames with errors.

  • ✗

    Active tap

    Why it's wrong here

    An active tap regenerates the signal before forwarding it, which can clean up errors and may drop malformed packets. It provides signal boosting but does not guarantee that errored packets are passed to the monitoring port. Therefore, it is not the best choice when errored packets must be captured.

  • ✗

    Regenerating tap

    Why it's wrong here

    A regenerating tap copies traffic and retransmits it to multiple monitoring ports. It ensures signal integrity but does not inherently capture errored packets; it may filter or drop malformed frames depending on configuration. It is not designed to include packets with errors.

  • ✗

    Aggregating tap

    Why it's wrong here

    An aggregating tap combines traffic from multiple links into a single monitoring port. While useful for consolidating traffic, it does not guarantee that errored packets are included; it may drop packets if the aggregate exceeds the monitoring port's bandwidth. It does not specifically address capturing errored frames.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.