Courseiva

SSCP Network and Communications Security Practice Question

An organization is deploying a network-based intrusion detection system (NIDS). The security team must decide on placement and configuration. Which THREE considerations are critical for effective NIDS deployment?

⚠ Common exam trap

SSCP often tests whether candidates confuse NIDS (detect and alert) with IPS (detect and block), leading them to select inline placement or packet-dropping options that are IPS characteristics.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Using a network tap or SPAN port to monitor traffic without introducing latency

Option A is correct because a NIDS is a passive monitoring technology, so it must receive a copy of traffic via a network TAP or a switch SPAN/mirror port; this preserves the monitored link's performance and avoids introducing latency or a failure point. Option D is correct because placing the NIDS behind the firewall on internal segments lets it inspect east-west traffic and detect insider threats or compromised hosts that perimeter filtering would miss. Option E is correct because signature tuning is essential: enabling only signatures relevant to the environment's OS, applications, and protocols reduces false positives and alert fatigue, keeping the IDS effective. Option B is not correct because inline placement is characteristic of an intrusion prevention system (IPS), not a NIDS, and it adds a potential latency and availability risk. Option C is not correct because dropping packets is an IPS blocking action; a NIDS only detects and alerts and cannot drop traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Using a network tap or SPAN port to monitor traffic without introducing latency

    Why this is correct

    A tap or SPAN port copies traffic to the NIDS passively, so monitoring introduces no inline latency or single point of failure. This satisfies the deployment constraint of inspecting traffic without disrupting production forwarding paths.

  • ✗

    Placing the NIDS inline to block malicious traffic immediately

    Why it's wrong here

    An inline NIDS becomes an intrusion prevention system, sitting in the traffic path and forwarding or dropping frames; a detection system passively mirrors or taps traffic, so inline placement risks outages and latency without matching the stem's detection-only requirement. Inline suits environments mandating active blocking.

  • ✗

    Configuring the NIDS to drop packets that match attack signatures

    Why it's wrong here

    Dropping signature-matched packets is prevention behaviour, which requires an IPS, not a NIDS; a detection system only alerts and logs, leaving enforcement to firewalls or IPS platforms. Packet-dropping configuration belongs in scenarios where active inline enforcement is explicitly required.

  • ✓

    Placing the NIDS on the internal network behind the firewall to detect insider threats

    Why this is correct

    Internal placement behind the firewall satisfies the insider-threat detection constraint: traffic between internal hosts never traverses the perimeter, so only a sensor on the trusted segment can inspect east-west flows and flag malicious internal activity.

  • ✓

    Tuning signatures to reduce false positives relevant to the environment

    Why this is correct

    Signature tuning suppresses alerts for benign activity specific to the environment, reducing false positives that otherwise overwhelm analysts. This satisfies the operational constraint that the NIDS remain effective and its alerts actionable rather than ignored.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.