Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Ethical Hacker

Domain 4Objective 3

Denial-of-Service and DDoS CEH Practice Questions (Page 2)

Part of the Network and Perimeter Hacking domain, which makes up ~9% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~9–14 in this domain), expect 2–3 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)

46questions here
10free pages
6concepts

Questions 6–10

  1. 6application · medium

    A security analyst is reviewing logs and finds that a server was overwhelmed by a large number of TCP SYN packets from many different source IPs, none of which completed the handshake. The analyst wants to identify the tool that could have been used to generate this attack. Which tool is most commonly associated with SYN floods?

    Select an answer first
  2. 7expert · hard

    A large online retailer is experiencing a DDoS attack that is a mix of UDP floods and HTTP GET floods. The company's on-premises mitigation appliance is struggling to keep up, and the ISP is threatening to null-route the company's IP if the attack continues. The company needs to maintain availability for customers. Which action is the most appropriate first step?

    Select an answer first
  3. 8application · medium

    A company's e-commerce site is suffering from a DDoS attack that is overwhelming the web servers with a mix of SYN floods and HTTP GET floods. The company wants to maintain service availability for legitimate users while minimizing infrastructure changes. Which mitigation approach is most appropriate?

    Select an answer first
  4. 9foundation · easy

    Which practice is a proactive countermeasure to reduce the impact of a DDoS attack?

    Select an answer first
  5. 10application · medium

    A security analyst is investigating a DDoS attack and finds that the attacking machines are sending traffic to a command-and-control server to receive instructions. The analyst also notices that the attack uses a technique where small queries are sent to publicly accessible servers, which then send large responses to the victim. Which two elements are present in this attack?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.