Courseiva
easyMultiple Choice

ISC2 CC Practice Question: Is configuring a network intrusion detection…

A security engineer is configuring a network intrusion detection system (NIDS) to monitor traffic on a critical subnet. To minimize false positives, which of the following should the engineer baseline first?

⚠ Common exam trap

ISC2 often tests the distinction between anomaly-based and signature-based detection, and the trap here is that candidates mistakenly think vulnerability scans or firewall logs provide a sufficient baseline, when in fact only observed normal traffic patterns during representative periods (like peak hours) can minimize false positives in an anomaly-based NIDS.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The normal traffic patterns during peak business hours

Baselining normal traffic patterns during peak business hours establishes a reference of legitimate network behavior, which is essential for a NIDS to distinguish benign anomalies from actual threats. Without this baseline, the NIDS may generate false positives by flagging legitimate peak-hour traffic spikes as malicious. This aligns with the principle that anomaly-based detection relies on a statistical model of normal activity to reduce noise.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The results of a recent vulnerability scan

    Why it's wrong here

    A vulnerability scan reports software weaknesses, not the normal traffic patterns a NIDS needs to distinguish benign from malicious flows. Baselining that scan would not reduce false positives. Vulnerability scan results would be correct input when prioritising patch remediation, not for tuning intrusion detection signatures.

  • ✓

    The normal traffic patterns during peak business hours

    Why this is correct

    Baselining normal peak-hour traffic patterns establishes what legitimate activity looks like, so the NIDS can flag only deviations. This directly satisfies the stem's constraint of minimising false positives, since signatures tuned to a known baseline avoid alerting on routine business traffic.

  • ✗

    The latest attack signatures from the vendor

    Why it's wrong here

    Attack signatures define what the NIDS detects, not what normal traffic looks like, so loading them cannot establish a baseline. Signature tuning is tempting because it directly reduces known detections, and would be the right focus when suppressing a specific documented exploit rather than learning the subnet's legitimate traffic patterns.

  • ✗

    The firewall logs from the past 24 hours

    Why it's wrong here

    Twenty-four hours of firewall logs capture only permitted and denied flows at the perimeter, not the full packet-level behaviour of the subnet, so they cannot establish a normal-traffic baseline. Firewall logs are tempting because they are readily available, and would suit investigating a specific blocked connection.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.