SSCP Risk Identification, Monitoring, and Analysis Practice Question
An organization uses a network-based intrusion detection system (NIDS). An analyst receives an alert for a known exploit signature. Which type of detection is the NIDS using?
⚠ Common exam trap
Test-takers frequently confuse 'signature-based' with 'heuristic' detection, because both involve pattern matching, but heuristic detection uses fuzzy logic or statistical models rather than exact known signatures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Signature-based detection
The NIDS generated an alert based on a known exploit signature, which means it compared network traffic against a database of predefined patterns or fingerprints of known attacks. This is the defining characteristic of signature-based detection, where the system relies on exact or pattern matches to known malicious activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Anomaly-based detection
Why it's wrong here
Anomaly-based detection builds a baseline of normal traffic and flags statistical deviations, whereas a known exploit signature is matched literally against a signature database. It is tempting because both raise alerts, but anomaly detection catches unknown activity, not predefined signature matches.
- ✗
Behavior-based detection
Why it's wrong here
Signature-based detection matches traffic against known exploit patterns; behaviour-based detection instead baselines normal activity and flags deviations, so a known signature alert does not indicate it. It is tempting because behaviour monitoring also detects attacks, but it identifies novel deviations rather than matching stored signatures.
- ✓
Signature-based detection
Why this is correct
The alert fired because traffic matched a stored pattern of a known exploit, which is precisely how signature-based detection works: it compares activity against a database of predefined attack signatures rather than profiling normal behaviour or anomalies.
- ✗
Heuristic detection
Why it's wrong here
Heuristic detection applies rules or scoring to infer suspicious intent in previously unseen activity; a known exploit signature is matched directly against a signature database. It is tempting because heuristics also identify attacks, but they generalise to new variants rather than matching stored signatures.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.