Courseiva

SSCP Risk Identification, Monitoring, and Analysis Practice Question

An organization uses a network-based intrusion detection system (NIDS). An analyst receives an alert for a known exploit signature. Which type of detection is the NIDS using?

⚠ Common exam trap

Test-takers frequently confuse 'signature-based' with 'heuristic' detection, because both involve pattern matching, but heuristic detection uses fuzzy logic or statistical models rather than exact known signatures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Signature-based detection

The NIDS generated an alert based on a known exploit signature, which means it compared network traffic against a database of predefined patterns or fingerprints of known attacks. This is the defining characteristic of signature-based detection, where the system relies on exact or pattern matches to known malicious activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Anomaly-based detection

    Why it's wrong here

    Anomaly-based detection builds a baseline of normal traffic and flags statistical deviations, whereas a known exploit signature is matched literally against a signature database. It is tempting because both raise alerts, but anomaly detection catches unknown activity, not predefined signature matches.

  • ✗

    Behavior-based detection

    Why it's wrong here

    Signature-based detection matches traffic against known exploit patterns; behaviour-based detection instead baselines normal activity and flags deviations, so a known signature alert does not indicate it. It is tempting because behaviour monitoring also detects attacks, but it identifies novel deviations rather than matching stored signatures.

  • ✓

    Signature-based detection

    Why this is correct

    The alert fired because traffic matched a stored pattern of a known exploit, which is precisely how signature-based detection works: it compares activity against a database of predefined attack signatures rather than profiling normal behaviour or anomalies.

  • ✗

    Heuristic detection

    Why it's wrong here

    Heuristic detection applies rules or scoring to infer suspicious intent in previously unseen activity; a known exploit signature is matched directly against a signature database. It is tempting because heuristics also identify attacks, but they generalise to new variants rather than matching stored signatures.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.