Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Ethical Hacker

Domain 4Objective 3

Denial-of-Service and DDoS CEH Practice Questions (Page 6)

Part of the Network and Perimeter Hacking domain, which makes up ~9% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~9–14 in this domain), expect 2–3 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)

46questions here
10free pages
6concepts

Questions 26–30

  1. 26expert · hard

    A security analyst is investigating a DDoS attack and discovers that the attack traffic is coming from a large number of IoT devices. The devices are sending DNS queries to open resolvers, which then send responses to the victim. The analyst also notices that the attack traffic is not spoofed; the source IPs are the actual IPs of the IoT devices. What is the most effective way to mitigate this attack?

    Select an answer first
  2. 27expert · hard

    A security analyst is analyzing a DDoS attack and finds that the attack traffic consists of TCP packets with the ACK flag set, but the packets are not part of any established connection. The packets are sent to a web server, causing it to process them and consume CPU resources. The source IPs are spoofed. What is the best mitigation?

    Select an answer first
  3. 28expert · hard

    A company's web application is under a sophisticated DDoS attack that uses a mix of SYN floods, UDP floods, and HTTP GET floods. The company has a cloud-based DDoS protection service, but the attack is still causing intermittent outages. The security team suspects that the protection service is not filtering some attack traffic. Which action should the team take first to improve the effectiveness of the protection?

    Select an answer first
  4. 29expert · hard

    A company is planning its DDoS incident response strategy. They have a critical web application and a limited budget. They want to ensure that the application remains available during a DDoS attack. Which approach should they prioritize?

    Select an answer first
  5. 30application · medium

    A security team is investigating a DDoS attack that used a large number of IoT devices to send traffic to a target. The devices were infected with malware that connected to a command-and-control (C2) server. Which technique would be most effective in disrupting the botnet's ability to coordinate further attacks?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.