Courseiva
Network Security →easyMultiple Choice

ISC2 CC Network Security Practice Question

A security analyst notices unusual traffic on the network and wants to capture packets for analysis without altering traffic. Which device should they use?

⚠ Common exam trap

The trap is confusing inline security devices (firewall, IPS, proxy) with passive monitoring devices; the exam tests that only a tap provides a non-intrusive copy of traffic without altering it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Network tap

A network tap is a passive hardware device inserted inline (or via a mirror port) that copies traffic to a monitoring port without altering or delaying the original traffic. This makes it ideal for packet capture and analysis because it provides a true copy of the wire traffic and does not introduce a point of failure or modify packets. Firewalls, IPS, and proxies are all inline devices that can alter or block traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Firewall

    Why it's wrong here

    A firewall filters traffic against rules and typically drops denied packets, so it cannot preserve an unaltered copy for analysis. It tempts because firewalls log connections and sit on the traffic path. A firewall is correct when the requirement is enforcing permitted or denied flows rather than capturing them.

  • ✗

    Intrusion Prevention System (IPS)

    Why it's wrong here

    An IPS sits inline and can drop or modify traffic to block threats, so it alters the packets it inspects, defeating passive capture. It tempts because IPS sensors do inspect traffic and log alerts. An IPS is correct when the requirement is active prevention rather than forensic collection.

  • ✗

    Proxy server

    Why it's wrong here

    A proxy terminates and regenerates connections, so captured packets reflect the proxy's sessions, not the original traffic, and it may block or cache requests. It tempts because proxies log and inspect web traffic. A proxy is correct when the goal is controlling or filtering outbound user requests.

  • ✓

    Network tap

    Why this is correct

    A network tap passively copies frames at the physical layer, delivering a duplicate stream to the capture device without introducing latency, dropping packets or altering traffic. This satisfies the requirement to capture packets for analysis while leaving the original traffic untouched.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.