
EC-CouncilCertified Ethical Hacker
Domain 4Objective 3
Denial-of-Service and DDoS CEH Practice Questions (Page 5)
Part of the Network and Perimeter Hacking domain, which makes up ~9% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~9–14 in this domain), expect 2–3 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
6concepts
Questions 21–25
- 21
A company's online service is down. The IT team finds that a single attacker is sending a continuous stream of ICMP echo requests to the server, overwhelming its ability to process legitimate traffic. Which term best describes this attack?
Select an answer first - 22
A penetration tester is conducting a DDoS simulation for a client. The tester wants to use a tool that can generate a low-and-slow attack to test the server's ability to handle many concurrent connections that are kept open. Which tool is most appropriate?
Select an answer first - 23
A small e-commerce company has experienced two DDoS attacks in the past month. They have a limited budget and cannot afford a commercial DDoS protection service. Their infrastructure consists of a single web server behind a firewall. Which combination of measures would provide the most cost-effective improvement in their resilience?
Select an answer first - 24
Which tool is commonly associated with simple, low-volume DDoS attacks and is often used by 'hacktivists'?
Select an answer first - 25
Which DDoS attack vector sends a high number of seemingly legitimate HTTP requests to a web server to exhaust its resources?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.