正解:A
Network sniffing is difficult to detect primarily because it can be performed passively. In CISM terms, a passive attack is one in which the attacker monitors or intercepts data without altering system resources or network traffic patterns. Because passive sniffing does not generate abnormal traffic, modify packets, or interact directly with target systems, it often leaves no observable indicators that traditional security monitoring tools can easily detect.
CISM distinguishes between passive and active attacks, emphasizing that passive techniques such as packet sniffing, eavesdropping, and traffic analysis are inherently harder to identify than active attacks, which disrupt operations or modify data. Continuous operation (B) does not explain detectability, active sniffing (C) would generate detectable anomalies, and remote execution (D) does not inherently make detection more difficult.
From an incident management and detection perspective, this highlights the importance of preventive controls, such as encryption, secure network design, and segmentation, rather than relying solely on detection mechanisms. Because passive sniffing exploits visibility rather than system weakness, prevention is the primary risk mitigation strategy.
References:
ISACA CISM Review Manual, Information Security Incident Management - attack types and detection challenges ISACA CISM Exam Content Outline, Domain 4: Information Security Incident Management