mediumMultiple Choice
ISC2 CC Practice Question: Has implemented a network-based intrusion…
An organization has implemented a network-based intrusion prevention system (IPS) in inline mode. After deployment, users report that legitimate web traffic is being blocked. What is the most likely cause?
⚠ Common exam trap
ISC2 often tests the distinction between inline and promiscuous modes, where candidates mistakenly think promiscuous mode can block traffic, but only inline mode allows active blocking.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The IPS signature set is too aggressive or includes false positives.
An inline IPS actively inspects and can block traffic based on its signature database. If the signature set is too aggressive or contains false positives, legitimate traffic matching those signatures will be incorrectly blocked. This is the most direct cause of blocking legitimate web traffic after deployment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The IPS is not receiving traffic due to a tap failure.
Why it's wrong here
A tap failure would stop traffic reaching the IPS entirely, producing no inspection and no blocking rather than false positives on legitimate web traffic. Taps are used for passive monitoring deployments, where the IPS would be the correct choice if out-of-band visibility without inline blocking were required.
- ✗
The IPS is placed behind the firewall instead of in front.
Why it's wrong here
Inline IPS placement relative to the firewall does not cause false positives; blocking legitimate traffic stems from overly aggressive signatures or thresholds. Positioning matters for traffic inspection coverage, and placing the IPS in front of the firewall would be chosen to filter malicious traffic before it reaches the firewall.
- ✗
The IPS is configured in promiscuous mode.
Why it's wrong here
Promiscuous mode makes the sensor monitor a copy of traffic without dropping packets, so it cannot block legitimate web traffic at all. It is tempting because promiscuous monitoring is the correct configuration for a passive, detection-only IDS deployment rather than an inline prevention deployment.
- ✓
The IPS signature set is too aggressive or includes false positives.
Why this is correct
Inline IPS blocks traffic matching enabled signatures. If legitimate web traffic is dropped, the signature set is likely too aggressive or contains false positives, so tuning or disabling those signatures restores legitimate traffic while preserving genuine threat detection.
Go deeper
Related to this question
Learn chapter
Network Security Components and Controls
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
Key term
IPS
An Intrusion Prevention System (IPS) is a network security device that monitors traffic in real time and automatically blocks threats before they reach your systems.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.