Courseiva
mediumMultiple SelectObjective-mapped

CISSP Practice Question: Which TWO of the following are effective methods…

Which TWO of the following are effective methods for detecting unauthorized access to a network? (Choose two.)

⚠ Common exam trap

It's easy for candidates to confuse vulnerability scanning (proactive) with intrusion detection (reactive), or assume antivirus covers network-level threats, when in fact neither provides real-time monitoring of network access attempts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Security information and event management (SIEM)

A SIEM aggregates and correlates logs from multiple sources (e.g., firewalls, servers, IDS) in real time, enabling detection of anomalous patterns indicative of unauthorized access. It provides centralized visibility and alerting that can identify a breach even when individual logs appear benign.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Vulnerability scanner

    Why it's wrong here

    A vulnerability scanner proactively identifies security weaknesses and misconfigurations in systems and applications by scanning for known flaws. While crucial for preventing unauthorized access by highlighting potential entry points, it does not actively monitor for or detect *ongoing* unauthorized access attempts or successful breaches in real-time. Its function is pre-emptive assessment, not incident detection.

  • Antivirus software

    Why it's wrong here

    Antivirus software primarily focuses on detecting, preventing, and removing malicious software such as viruses, worms, and Trojans from endpoints. While malware can be a *tool* for unauthorized access, antivirus solutions are not designed to directly identify unauthorized human logins, privilege escalation, or lateral movement across a network unless those actions involve known malware signatures or behaviors.

  • Security information and event management (SIEM)

    Why this is correct

    A Security Information and Event Management (SIEM) system aggregates and correlates security event data from various sources, including network devices, servers, applications, and intrusion detection systems. By analyzing these logs in real-time for anomalous patterns, policy violations, and known attack signatures, SIEM can effectively detect sophisticated unauthorized access attempts and ongoing breaches that might otherwise go unnoticed.

  • Firewall rule review

    Why it's wrong here

    Firewall rule review is a crucial administrative control focused on ensuring that network access policies are correctly implemented and maintained. This process aims to prevent unauthorized access by blocking unwanted traffic, but it is a static, periodic activity and does not actively monitor for or detect real-time unauthorized access attempts or successful circumvention of existing rules.

  • Intrusion detection system (IDS)

    Why this is correct

    An Intrusion Detection System (IDS) continuously monitors network traffic or system activities for suspicious patterns, known attack signatures, or deviations from normal behavior. Upon detecting potential unauthorized access or malicious activity, an IDS generates alerts, providing real-time notification of ongoing or attempted intrusions, making it a primary detection mechanism.

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.