Courseiva
mediumMultiple Choice

ISC2 CC Practice Question: Wants to detect and alert on potential network…

An organization wants to detect and alert on potential network intrusions but does not want to risk blocking legitimate traffic. Which system should they deploy?

⚠ Common exam trap

ISC2 often tests the distinction between detection (IDS) and prevention (IPS) by emphasizing that an IDS is passive and out-of-band, while an IPS is inline and can block traffic, so the trap here is confusing the alert-only capability of NIDS with the active blocking of NIPS or UTM appliances.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Network-based Intrusion Detection System (NIDS)

A Network-based Intrusion Detection System (NIDS) passively monitors network traffic and generates alerts when suspicious patterns are detected, but it does not take any inline action to block traffic. This makes it the correct choice for an organization that wants to detect and alert on potential intrusions without any risk of blocking legitimate traffic, as the NIDS operates out-of-band and cannot drop packets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Network-based Intrusion Detection System (NIDS)

    Why this is correct

    A NIDS passively monitors network traffic and raises alerts on suspicious patterns without sitting inline, so it cannot drop or block legitimate packets. This satisfies the requirement to detect and alert on intrusions while avoiding any risk of blocking valid traffic.

  • ✗

    Unified Threat Management (UTM) appliance

    Why it's wrong here

    A UTM appliance bundles firewall, IPS and gateway filtering, so it can block traffic when any module matches, violating the no-blocking requirement. It is tempting because UTM consolidates several security functions in one device, and would be correct for a small site wanting unified perimeter enforcement rather than passive detection.

  • ✗

    Firewall with deep packet inspection

    Why it's wrong here

    Deep packet inspection on a firewall can drop traffic when signatures match, so it risks blocking legitimate flows rather than only alerting. It is tempting because DPI inspects payloads at layer 7 and is genuinely the right choice when the requirement is to enforce application-level policy, not merely detect.

  • ✗

    Network-based Intrusion Prevention System (NIPS)

    Why it's wrong here

    A NIPS sits inline and actively drops or resets offending sessions, directly contradicting the no-blocking requirement. It is tempting because NIPS offers the same signature-based intrusion detection as an IDS, and would be correct where the organisation wants prevention enforced automatically rather than alerts alone.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.