SSCP Network and Communications Security Practice Question
A security administrator is configuring a network intrusion detection system (NIDS) to monitor traffic for signs of attacks. The administrator wants to ensure the NIDS can detect attacks that involve fragmented packets. Which of the following should be enabled on the NIDS to reassemble fragmented packets before analysis?
⚠ Common exam trap
A common mix-up: candidates confuse stream reassembly, which rebuilds TCP sessions, with IP defragmentation, which rebuilds fragmented IP packets.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IP defragmentation
IP defragmentation is necessary for a NIDS to reassemble fragmented IP packets before inspecting them. Fragmentation is a common evasion technique where attackers split malicious payloads across multiple packets to avoid detection. By enabling IP defragmentation, the NIDS can reconstruct the original packet and analyze it for threats. Stream reassembly and other options do not address IP-layer fragmentation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
TCP segmentation offload
Why it's wrong here
TCP segmentation offload (TSO) is a hardware feature that offloads the segmentation of TCP packets to the network interface card. It is used to improve performance by reducing CPU overhead, not for security analysis. It does not help in reassembling fragmented IP packets and is not a feature of NIDS. Therefore, it is incorrect for this scenario.
- ✓
IP defragmentation
Why this is correct
IP defragmentation is the process of reassembling fragmented IP packets into complete packets before analysis. Attackers often use fragmentation to evade detection by splitting malicious payloads across multiple fragments. Enabling IP defragmentation on the NIDS allows it to reconstruct the original packet and inspect it for malicious content. This is essential for detecting fragmentation-based attacks, making it the correct choice.
- ✗
Application layer gateway
Why it's wrong here
An application layer gateway (ALG) is a security component that understands specific application protocols and can filter or modify traffic. It operates at the application layer and does not perform IP defragmentation. While ALGs can help with certain types of attacks, they are not used to reassemble fragmented packets at the network layer. Thus, it is not the correct answer.
- ✗
Stream reassembly
Why it's wrong here
Stream reassembly is used to reconstruct TCP sessions from individual packets, allowing the NIDS to analyze the full conversation. It does not specifically address IP fragmentation, which occurs at the network layer. While it is important for detecting application-layer attacks, it does not reassemble fragmented IP packets. Therefore, it is not the correct feature to enable for this scenario.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.