Courseiva
mediumMultiple Choice

ISC2 CC Practice Question: Has implemented a network-based intrusion…

An organization has implemented a network-based intrusion prevention system (IPS) in inline mode. After deployment, users report that legitimate web traffic is being blocked. What is the most likely cause?

⚠ Common exam trap

ISC2 often tests the distinction between inline and promiscuous modes, where candidates mistakenly think promiscuous mode can block traffic, but only inline mode allows active blocking.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The IPS signature set is too aggressive or includes false positives.

An inline IPS actively inspects and can block traffic based on its signature database. If the signature set is too aggressive or contains false positives, legitimate traffic matching those signatures will be incorrectly blocked. This is the most direct cause of blocking legitimate web traffic after deployment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The IPS is not receiving traffic due to a tap failure.

    Why it's wrong here

    A tap failure would stop traffic reaching the IPS entirely, producing no inspection and no blocking rather than false positives on legitimate web traffic. Taps are used for passive monitoring deployments, where the IPS would be the correct choice if out-of-band visibility without inline blocking were required.

  • ✗

    The IPS is placed behind the firewall instead of in front.

    Why it's wrong here

    Inline IPS placement relative to the firewall does not cause false positives; blocking legitimate traffic stems from overly aggressive signatures or thresholds. Positioning matters for traffic inspection coverage, and placing the IPS in front of the firewall would be chosen to filter malicious traffic before it reaches the firewall.

  • ✗

    The IPS is configured in promiscuous mode.

    Why it's wrong here

    Promiscuous mode makes the sensor monitor a copy of traffic without dropping packets, so it cannot block legitimate web traffic at all. It is tempting because promiscuous monitoring is the correct configuration for a passive, detection-only IDS deployment rather than an inline prevention deployment.

  • ✓

    The IPS signature set is too aggressive or includes false positives.

    Why this is correct

    Inline IPS blocks traffic matching enabled signatures. If legitimate web traffic is dropped, the signature set is likely too aggressive or contains false positives, so tuning or disabling those signatures restores legitimate traffic while preserving genuine threat detection.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.