SSCP Network and Communications Security Practice Question
A security engineer is deploying a Network Intrusion Detection System (NIDS) on a switched network. The engineer needs to ensure the NIDS can monitor all traffic passing through a critical switch port that connects to a server. Which technology should be configured on the switch to copy traffic from the server port to the NIDS monitoring port?
⚠ Common exam trap
The trap here is assuming that any port that carries traffic (like a trunk or LACP bundle) will automatically provide full visibility to a monitoring device.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Port mirroring (SPAN)
Port mirroring (SPAN) is the correct technology because it copies traffic from a source port to a destination port, allowing a NIDS to monitor all traffic without being inline. STP, VLAN trunking, and LACP serve different purposes: loop prevention, carrying multiple VLANs, and link aggregation, respectively. None of them replicate traffic to a monitoring port. Port mirroring is essential for passive monitoring in switched environments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Link Aggregation Control Protocol (LACP)
Why it's wrong here
LACP bundles multiple physical links into a single logical link to increase bandwidth and provide redundancy. It does not copy traffic to another port. A NIDS connected to an LACP bundle would only see its own share of traffic based on hashing, not all traffic from the server port. Therefore, LACP is not suitable for monitoring.
- ✓
Port mirroring (SPAN)
Why this is correct
Port mirroring, often called Switched Port Analyzer (SPAN) on Cisco switches, copies frames from one or more source ports to a designated destination port where a monitoring device is connected. This allows the NIDS to see all traffic passing through the server port without disrupting network flow. It is the standard method for enabling intrusion detection on switched networks.
- ✗
Spanning Tree Protocol (STP)
Why it's wrong here
STP is used to prevent loops in a switched network by creating a loop-free logical topology. It does not copy traffic from one port to another. Enabling STP would not provide the NIDS with visibility into the server's traffic; it only affects how switches forward frames to avoid broadcast storms and loops. Therefore, it does not meet the monitoring requirement.
- ✗
Virtual LAN (VLAN) trunking
Why it's wrong here
VLAN trunking uses 802.1Q to carry multiple VLANs over a single link between switches. It does not replicate traffic to a monitoring port. While a trunk port can carry traffic from many VLANs, connecting a NIDS to a trunk port would only see traffic destined for that trunk, not a copy of the server's traffic. Thus, it does not satisfy the requirement.
Visual reference
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.