ISC2 CC Network Security Practice Question
What is the primary difference between an IDS and an IPS?
⚠ Common exam trap
The trap is confusing the deployment mode (inline vs. out-of-band) with the response capability; the exam tests that the key difference is alert-only vs. block, not speed, form factor, or scope.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IDS only alerts, IPS can block traffic
The primary difference is that an IDS (Intrusion Detection System) is passive and only alerts on suspicious activity, while an IPS (Intrusion Prevention System) is inline and can actively block or drop malicious traffic. Both can monitor network or host activity, but the key distinction is the response capability: detect vs. detect and prevent.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
IDS is faster than IPS
Why it's wrong here
Neither device is inherently faster; both inspect the same traffic at comparable line rates, and latency depends on deployment and configuration. It is tempting because inline blocking sounds slower than passive monitoring, but the real axis of difference is whether the device can drop malicious traffic or only alert.
- ✗
IDS is hardware, IPS is software
Why it's wrong here
Both IDS and IPS are available as software, appliances or virtual instances, so form factor does not separate them. It is tempting because many IDS deployments are software-based, but the genuine difference is that an IPS sits inline and blocks traffic while an IDS passively detects and alerts.
- ✗
IDS monitors only hosts, IPS monitors network
Why it's wrong here
Both IDS and IPS can be deployed as network or host-based variants, so neither is restricted to one scope. It is tempting because network IDS is the commonest deployment, but the actual distinction is response capability: detection and alerting versus inline prevention.
- ✓
IDS only alerts, IPS can block traffic
Why this is correct
An IDS passively monitors copies of traffic and raises alerts, leaving response to administrators. An IPS sits inline on the traffic path, so it can drop malicious packets or reset connections in real time. That inline blocking capability, absent from an alert-only IDS, is the defining difference the question asks for.
Go deeper
Related to this question
Learn chapter
Network Security Foundations
Key term
Intrusion Prevention System
An Intrusion Prevention System (IPS) is a network security tool that monitors network traffic and actively blocks threats like malware and cyberattacks in real time.
Key term
IPS
An Intrusion Prevention System (IPS) is a network security device that monitors traffic in real time and automatically blocks threats before they reach your systems.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.