Courseiva

SSCP Risk Identification, Monitoring, and Analysis Practice Question

A security analyst is reviewing alerts from a Network Intrusion Detection System (NIDS) that monitors a demilitarized zone segment. Over one week, the same alert fires hundreds of times for traffic that the business has confirmed is a legitimate partner integration. The analyst has verified the signature is correctly written and the traffic is truly benign. What is the most appropriate action?

⚠ Common exam trap

The trap here is treating verified benign traffic as a reason to remove or disable the detection, rather than tuning it narrowly to preserve coverage.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a tuned exception or suppression rule scoped to the specific signature, source, and destination of the partner traffic.

When a signature is accurate but a verified benign source repeatedly triggers it, targeted suppression is the proportionate response. Scoping the exception to the exact signature, source, and destination eliminates the noise without weakening detection elsewhere. Deleting the signature or disabling the sensor would create blind spots, and raising severity would simply escalate benign alerts for manual review.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable the NIDS sensor on the DMZ segment to stop the noise until the partner integration is retired.

    Why it's wrong here

    Disabling the sensor removes all visibility into the DMZ, including genuine attacks, which is a severe reduction in detection capability. The noise originates from one verified benign pattern, not from the sensor itself. Turning off monitoring to silence a single false-positive source trades a small annoyance for a large blind spot and is not appropriate.

  • ✗

    Increase the alert severity of the signature so that analysts investigate every occurrence manually.

    Why it's wrong here

    Raising severity does not reduce the volume of benign alerts; it merely escalates them. Analysts would still spend time on confirmed-benign events, and the higher priority could crowd out genuine incidents. Severity escalation is used for high-risk detections, not for managing a known false-positive pattern from an approved integration.

  • ✓

    Create a tuned exception or suppression rule scoped to the specific signature, source, and destination of the partner traffic.

    Why this is correct

    Since the signature is accurate and the traffic is verified benign, the correct response is targeted tuning that suppresses only that pattern while preserving the signature for all other traffic. Scoping the exception to the exact source, destination, and signature keeps detection coverage intact for genuinely malicious activity on the DMZ segment.

  • ✗

    Delete the signature from the NIDS rule set and rely on firewall logs for DMZ monitoring.

    Why it's wrong here

    Deleting the signature eliminates detection for that technique across all traffic, including malicious use by other actors. Firewall logs lack the deep packet inspection needed to replace NIDS coverage. Removing a valid detection because one partner triggers it is disproportionate and weakens the overall monitoring posture on the DMZ segment.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.