Courseiva
hardMultiple Choice

SSCP Practice Question: A network has multiple VLANs with an IDS deployed…

A network has multiple VLANs with an IDS deployed on the core switch using SPAN ports. The IDS is missing some packets during high traffic periods. What is the best course of action to improve packet capture reliability?

⚠ Common exam trap

ISC2 often tests the misconception that increasing buffers or adding more SPAN sessions can solve packet loss, when the real issue is the inherent unreliability of SPAN port replication under high load, making inline deployment the only guaranteed solution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy the IDS inline

Deploying the IDS inline ensures that all traffic destined for the monitored segment must pass through the device, eliminating packet loss caused by oversubscription of SPAN ports during high traffic periods. SPAN ports rely on switch fabric replication, which can drop packets when the aggregate traffic exceeds the port's bandwidth or the switch's internal buffer capacity. Inline deployment places the IDS directly in the data path, guaranteeing that every packet is inspected without reliance on replication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Deploy the IDS inline

    Why this is correct

    SPAN ports drop frames once the mirror session exceeds interface or ASIC capacity, which explains the missed packets. An inline IDS receives every frame in the forwarding path, so nothing is discarded under load, satisfying the reliability constraint the stem describes.

  • ✗

    Implement NetFlow for monitoring

    Why it's wrong here

    NetFlow exports flow metadata — source, destination, ports, byte counts — not full packet payloads, so the IDS loses the content it needs for signature inspection. Flow telemetry is the right choice for traffic profiling and anomaly baselining, but it cannot reconstruct the dropped packets the sensor must analyse.

  • ✗

    Use multiple SPAN sessions

    Why it's wrong here

    Additional SPAN sessions merely duplicate the same mirrored traffic across more destination ports; they do not raise the aggregate mirroring capacity or stop the switch ASIC from dropping frames when the copy exceeds port bandwidth. Multiple sessions suit tapping several VLAN groups separately, not relieving oversubscription on one congested capture link.

  • ✗

    Increase the SPAN port buffer

    Why it's wrong here

    SPAN destination port buffering is not a tunable parameter on most switches; drops occur because mirrored traffic exceeds the destination link's line rate, and a larger queue only delays the overflow. Buffer tuning belongs to interface QoS configuration, whereas the fix here is a dedicated TAP or aggregator that mirrors at full line rate.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.