Courseiva

SSCP Network and Communications Security Practice Question

A security administrator is configuring a network intrusion detection system (NIDS) to monitor traffic for signs of attacks. The administrator wants to ensure the NIDS can detect attacks that involve fragmented packets. Which of the following should be enabled on the NIDS to reassemble fragmented packets before analysis?

⚠ Common exam trap

A common mix-up: candidates confuse stream reassembly, which rebuilds TCP sessions, with IP defragmentation, which rebuilds fragmented IP packets.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IP defragmentation

IP defragmentation is necessary for a NIDS to reassemble fragmented IP packets before inspecting them. Fragmentation is a common evasion technique where attackers split malicious payloads across multiple packets to avoid detection. By enabling IP defragmentation, the NIDS can reconstruct the original packet and analyze it for threats. Stream reassembly and other options do not address IP-layer fragmentation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    TCP segmentation offload

    Why it's wrong here

    TCP segmentation offload (TSO) is a hardware feature that offloads the segmentation of TCP packets to the network interface card. It is used to improve performance by reducing CPU overhead, not for security analysis. It does not help in reassembling fragmented IP packets and is not a feature of NIDS. Therefore, it is incorrect for this scenario.

  • ✓

    IP defragmentation

    Why this is correct

    IP defragmentation is the process of reassembling fragmented IP packets into complete packets before analysis. Attackers often use fragmentation to evade detection by splitting malicious payloads across multiple fragments. Enabling IP defragmentation on the NIDS allows it to reconstruct the original packet and inspect it for malicious content. This is essential for detecting fragmentation-based attacks, making it the correct choice.

  • ✗

    Application layer gateway

    Why it's wrong here

    An application layer gateway (ALG) is a security component that understands specific application protocols and can filter or modify traffic. It operates at the application layer and does not perform IP defragmentation. While ALGs can help with certain types of attacks, they are not used to reassemble fragmented packets at the network layer. Thus, it is not the correct answer.

  • ✗

    Stream reassembly

    Why it's wrong here

    Stream reassembly is used to reconstruct TCP sessions from individual packets, allowing the NIDS to analyze the full conversation. It does not specifically address IP fragmentation, which occurs at the network layer. While it is important for detecting application-layer attacks, it does not reassemble fragmented IP packets. Therefore, it is not the correct feature to enable for this scenario.

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.