Courseiva

SSCP Risk Identification, Monitoring, and Analysis Practice Question

An analyst is reviewing alerts from a network-based intrusion detection system (NIDS) deployed on a span port at the internet edge. Several alerts reference exploit attempts against services that are not exposed to the internet. Which TWO actions should the analyst take to improve the fidelity of the monitoring data? (Choose two.)

⚠ Common exam trap

The trap here is assuming noisy alerts require blocking or severity escalation, when the real issue is signature scope and what traffic the sensor actually receives.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify the span port configuration and confirm which VLANs and interfaces are actually mirrored

Alerts against services that are not actually reachable indicate a mismatch between what the sensor is configured to detect or see and the environment it protects. Restricting signatures to the real exposed services removes irrelevant detections, and validating the span port mirroring confirms the sensor is observing the intended segment, so alerts can be trusted to reflect genuine attack surface.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Verify the span port configuration and confirm which VLANs and interfaces are actually mirrored

    Why this is correct

    A span port that mirrors the wrong VLANs or an incorrect interface set can feed the NIDS traffic from internal segments, making internal-only services appear internet-facing in alerts. Confirming exactly what is mirrored establishes ground truth about what the sensor can see, which is essential before drawing conclusions from any alert and prevents misinterpretation of where attacks actually occurred.

  • ✗

    Increase the alert severity of all exploit signatures to critical to ensure they are reviewed

    Why it's wrong here

    Raising severity on signatures that are firing against non-existent services amplifies noise rather than reducing it, flooding queues with alerts that carry no real risk. Severity should reflect genuine business impact and exploitability; blanket escalation masks meaningful alerts and accelerates analyst fatigue, which is the opposite of improving monitoring fidelity.

  • ✗

    Enable blocking mode so the NIDS drops packets matching the noisy signatures

    Why it's wrong here

    A NIDS passively analyzes copies of traffic and has no inline position from which to drop packets; converting it to blocking behavior changes it into an intrusion prevention system and requires inline deployment. Enabling drop actions on a span-port sensor is technically unworkable and would not address the mismatch between signatures and exposed services.

  • ✗

    Disable all exploit-class signatures and rely solely on anomaly-based detection

    Why it's wrong here

    Removing the entire exploit signature class eliminates detection for real attacks against exposed services and abandons the precision that signature matching provides. Anomaly-based detection alone produces baseline-dependent results and higher false positive rates, so replacing rather than tuning signatures degrades coverage instead of improving the quality of the monitoring data.

  • ✓

    Tune the NIDS signature set to match the services actually exposed on the monitored segment

    Why this is correct

    Signatures written for services that do not exist on the monitored segment generate alerts with no actionable meaning, inflating noise and eroding analyst trust. Aligning the enabled signature set with the actual exposed services reduces irrelevant detections while preserving coverage for real threats, directly improving the signal-to-noise ratio of the monitoring data without weakening protection for legitimate attack surface.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.