SSCP Risk Identification, Monitoring, and Analysis Practice Question
An analyst is reviewing alerts from a network-based intrusion detection system (NIDS) deployed on a span port at the internet edge. Several alerts reference exploit attempts against services that are not exposed to the internet. Which TWO actions should the analyst take to improve the fidelity of the monitoring data? (Choose two.)
⚠ Common exam trap
The trap here is assuming noisy alerts require blocking or severity escalation, when the real issue is signature scope and what traffic the sensor actually receives.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify the span port configuration and confirm which VLANs and interfaces are actually mirrored
Alerts against services that are not actually reachable indicate a mismatch between what the sensor is configured to detect or see and the environment it protects. Restricting signatures to the real exposed services removes irrelevant detections, and validating the span port mirroring confirms the sensor is observing the intended segment, so alerts can be trusted to reflect genuine attack surface.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Verify the span port configuration and confirm which VLANs and interfaces are actually mirrored
Why this is correct
A span port that mirrors the wrong VLANs or an incorrect interface set can feed the NIDS traffic from internal segments, making internal-only services appear internet-facing in alerts. Confirming exactly what is mirrored establishes ground truth about what the sensor can see, which is essential before drawing conclusions from any alert and prevents misinterpretation of where attacks actually occurred.
- ✗
Increase the alert severity of all exploit signatures to critical to ensure they are reviewed
Why it's wrong here
Raising severity on signatures that are firing against non-existent services amplifies noise rather than reducing it, flooding queues with alerts that carry no real risk. Severity should reflect genuine business impact and exploitability; blanket escalation masks meaningful alerts and accelerates analyst fatigue, which is the opposite of improving monitoring fidelity.
- ✗
Enable blocking mode so the NIDS drops packets matching the noisy signatures
Why it's wrong here
A NIDS passively analyzes copies of traffic and has no inline position from which to drop packets; converting it to blocking behavior changes it into an intrusion prevention system and requires inline deployment. Enabling drop actions on a span-port sensor is technically unworkable and would not address the mismatch between signatures and exposed services.
- ✗
Disable all exploit-class signatures and rely solely on anomaly-based detection
Why it's wrong here
Removing the entire exploit signature class eliminates detection for real attacks against exposed services and abandons the precision that signature matching provides. Anomaly-based detection alone produces baseline-dependent results and higher false positive rates, so replacing rather than tuning signatures degrades coverage instead of improving the quality of the monitoring data.
- ✓
Tune the NIDS signature set to match the services actually exposed on the monitored segment
Why this is correct
Signatures written for services that do not exist on the monitored segment generate alerts with no actionable meaning, inflating noise and eroding analyst trust. Aligning the enabled signature set with the actual exposed services reduces irrelevant detections while preserving coverage for real threats, directly improving the signal-to-noise ratio of the monitoring data without weakening protection for legitimate attack surface.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.