Courseiva
mediumMultiple ChoiceObjective-mapped

ISC2 CC Practice Question: Wants to detect and alert on potential network…

An organization wants to detect and alert on potential network intrusions but does not want to risk blocking legitimate traffic. Which system should they deploy?

⚠ Common exam trap

ISC2 often tests the distinction between detection (IDS) and prevention (IPS) by emphasizing that an IDS is passive and out-of-band, while an IPS is inline and can block traffic, so the trap here is confusing the alert-only capability of NIDS with the active blocking of NIPS or UTM appliances.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Network-based Intrusion Detection System (NIDS)

A Network-based Intrusion Detection System (NIDS) passively monitors network traffic and generates alerts when suspicious patterns are detected, but it does not take any inline action to block traffic. This makes it the correct choice for an organization that wants to detect and alert on potential intrusions without any risk of blocking legitimate traffic, as the NIDS operates out-of-band and cannot drop packets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Network-based Intrusion Detection System (NIDS)

    Why this is correct

    A NIDS is passive and only alerts on potential intrusions without blocking traffic, avoiding false positives that block legitimate traffic.

  • Unified Threat Management (UTM) appliance

    Why it's wrong here

    UTM includes multiple functions often including blocking, which may block legitimate traffic.

  • Firewall with deep packet inspection

    Why it's wrong here

    A firewall with DPI can block traffic, presenting a risk of blocking legitimate traffic.

  • Network-based Intrusion Prevention System (NIPS)

    Why it's wrong here

    A NIPS blocks traffic inline, which could block legitimate traffic.

About these practice questions

Courseiva writes every CC question from scratch — 976 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.