mediumMultiple ChoiceObjective-mapped
ISC2 CC Practice Question: Wants to detect and alert on potential network…
An organization wants to detect and alert on potential network intrusions but does not want to risk blocking legitimate traffic. Which system should they deploy?
⚠ Common exam trap
ISC2 often tests the distinction between detection (IDS) and prevention (IPS) by emphasizing that an IDS is passive and out-of-band, while an IPS is inline and can block traffic, so the trap here is confusing the alert-only capability of NIDS with the active blocking of NIPS or UTM appliances.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Network-based Intrusion Detection System (NIDS)
A Network-based Intrusion Detection System (NIDS) passively monitors network traffic and generates alerts when suspicious patterns are detected, but it does not take any inline action to block traffic. This makes it the correct choice for an organization that wants to detect and alert on potential intrusions without any risk of blocking legitimate traffic, as the NIDS operates out-of-band and cannot drop packets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Network-based Intrusion Detection System (NIDS)
Why this is correct
A NIDS is passive and only alerts on potential intrusions without blocking traffic, avoiding false positives that block legitimate traffic.
- ✗
Unified Threat Management (UTM) appliance
Why it's wrong here
UTM includes multiple functions often including blocking, which may block legitimate traffic.
- ✗
Firewall with deep packet inspection
Why it's wrong here
A firewall with DPI can block traffic, presenting a risk of blocking legitimate traffic.
- ✗
Network-based Intrusion Prevention System (NIPS)
Why it's wrong here
A NIPS blocks traffic inline, which could block legitimate traffic.
Go deeper
Related to this question
Learn chapter
Risk Management and Security Controls
Key term
Alert
An alert is a notification that something unusual or potentially harmful has happened in a computer system or network.
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
About these practice questions
Courseiva writes every CC question from scratch — 976 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.