SSCP Network and Communications Security Practice Question
A company wants to deploy a network IDS that can analyze traffic patterns and detect anomalies. Where should the IDS sensor be placed to monitor all traffic on a network segment without introducing latency?
⚠ Common exam trap
SSCP often tests the confusion between inline (IPS, adds latency) and out-of-band (IDS, passive) deployments — candidates pick 'inline' thinking it guarantees visibility, but it violates the no-latency requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Connected to a switch SPAN port
A SPAN (Switched Port Analyzer) port mirrors traffic from one or more switch ports or VLANs to a dedicated monitoring port, allowing the IDS sensor to receive a copy of the traffic passively. Because the sensor is not in the forwarding path, it introduces zero latency to production traffic while still seeing all frames on the monitored segment. This is the canonical out-of-band IDS deployment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Inline between the router and the switch
Why it's wrong here
Placing the sensor inline forces every packet through it, adding processing delay and creating a single point of failure, which contradicts the no-latency requirement. Inline placement is correct when the IDS must actively block malicious traffic rather than merely observe it passively.
- ✗
At the core switch as a transparent bridge
Why it's wrong here
A transparent bridge at the core switch still forwards frames at wire speed, but it only sees traffic traversing that specific segment, so it cannot monitor every segment the question demands. It is tempting because transparent bridging is genuinely used to insert sensors without altering topology or adding hops.
- ✗
On the same segment as the router
Why it's wrong here
Placing the sensor on the router's segment captures only traffic traversing that segment, missing intra-segment flows, and inline placement adds latency. It is tempting because routers aggregate traffic, and would be correct for monitoring inter-segment routing rather than full segment visibility.
- ✓
Connected to a switch SPAN port
Why this is correct
A SPAN port mirrors copies of frames from the monitored segment to the sensor, so the IDS analyses traffic passively without sitting inline in the forwarding path. This satisfies the requirement to monitor all segment traffic without introducing latency.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.