
EC-CouncilCertified Ethical Hacker
Domain 4Objective 3
Denial-of-Service and DDoS CEH Practice Questions (Page 3)
Part of the Network and Perimeter Hacking domain, which makes up ~9% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~9–14 in this domain), expect 2–3 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
6concepts
Questions 11–15
- 11
A security analyst is investigating a DDoS attack that used a botnet of compromised web servers to send HTTP requests to a target. The analyst discovers that the botnet is using a peer-to-peer (P2P) C2 mechanism, making it difficult to shut down. Which mitigation strategy would be most effective in disrupting this botnet?
Select an answer first - 12
A company's network is experiencing a DDoS attack that is saturating their internet link. The attack is a mix of UDP and ICMP floods. The company has a DDoS protection service, but the service is not activated. What should the company do first?
Select an answer first - 13
Which mitigation technique involves limiting the rate of traffic from a specific source to prevent overwhelming a server?
Select an answer first - 14
A regional e-commerce site experiences intermittent outages during peak shopping hours. Network logs show a flood of TCP SYN packets to the web server from thousands of distinct source IPs, but each source sends only a few packets. The server's connection table fills up, and legitimate users cannot establish new sessions. Which mitigation approach should the security team implement FIRST to restore service while minimizing impact on legitimate traffic?
Select an answer first - 15
A company's website is under an application-layer DDoS attack that sends HTTP requests with a very high rate of unique User-Agent strings. The attack is causing high CPU usage on the web servers. The company has a WAF, but the WAF's default rules are not blocking the attack. What should the security team do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.