hardMultiple Choice
SSCP Practice Question: A network has multiple VLANs with an IDS deployed…
A network has multiple VLANs with an IDS deployed on the core switch using SPAN ports. The IDS is missing some packets during high traffic periods. What is the best course of action to improve packet capture reliability?
⚠ Common exam trap
ISC2 often tests the misconception that increasing buffers or adding more SPAN sessions can solve packet loss, when the real issue is the inherent unreliability of SPAN port replication under high load, making inline deployment the only guaranteed solution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy the IDS inline
Deploying the IDS inline ensures that all traffic destined for the monitored segment must pass through the device, eliminating packet loss caused by oversubscription of SPAN ports during high traffic periods. SPAN ports rely on switch fabric replication, which can drop packets when the aggregate traffic exceeds the port's bandwidth or the switch's internal buffer capacity. Inline deployment places the IDS directly in the data path, guaranteeing that every packet is inspected without reliance on replication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Deploy the IDS inline
Why this is correct
SPAN ports drop frames once the mirror session exceeds interface or ASIC capacity, which explains the missed packets. An inline IDS receives every frame in the forwarding path, so nothing is discarded under load, satisfying the reliability constraint the stem describes.
- ✗
Implement NetFlow for monitoring
Why it's wrong here
NetFlow exports flow metadata — source, destination, ports, byte counts — not full packet payloads, so the IDS loses the content it needs for signature inspection. Flow telemetry is the right choice for traffic profiling and anomaly baselining, but it cannot reconstruct the dropped packets the sensor must analyse.
- ✗
Use multiple SPAN sessions
Why it's wrong here
Additional SPAN sessions merely duplicate the same mirrored traffic across more destination ports; they do not raise the aggregate mirroring capacity or stop the switch ASIC from dropping frames when the copy exceeds port bandwidth. Multiple sessions suit tapping several VLAN groups separately, not relieving oversubscription on one congested capture link.
- ✗
Increase the SPAN port buffer
Why it's wrong here
SPAN destination port buffering is not a tunable parameter on most switches; drops occur because mirrored traffic exceeds the destination link's line rate, and a larger queue only delays the overflow. Buffer tuning belongs to interface QoS configuration, whereas the fix here is a dedicated TAP or aggregator that mirrors at full line rate.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.