Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Ethical Hacker

Domain 4Objective 3

Denial-of-Service and DDoS CEH Practice Questions (Page 7)

Part of the Network and Perimeter Hacking domain, which makes up ~9% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~9–14 in this domain), expect 2–3 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)

46questions here
10free pages
6concepts

Questions 31–35

  1. 31application · medium

    A company wants to minimize the impact of a DDoS attack on its public-facing web servers. They have a limited budget and want to implement a cost-effective measure that can be deployed quickly. Which action is most appropriate?

    Select an answer first
  2. 32foundation · easy

    Which network hardening measure helps prevent your systems from being used as DDoS amplifiers?

    Select an answer first
  3. 33expert · hard

    A company is designing its DDoS incident response plan. The plan must balance the need to maintain service availability with the need to preserve forensic evidence for potential legal action. Which approach best achieves this balance?

    Select an answer first
  4. 34application · medium

    A security analyst notices a sudden spike in DNS queries from many different resolvers to the company's authoritative DNS server. The queries are for a single domain and are all of type ANY. The responses are much larger than the queries. The analyst suspects a reflection attack. Which defensive measure would be most effective in reducing the impact of this attack?

    Select an answer first
  5. 35application · medium

    A hacktivist group announces a campaign against a financial institution. During the attack, the institution's public website becomes slow, but the internal network and customer databases remain unaffected. The attack traffic consists of HTTP GET requests for a single large webpage, each request coming from a different IP address. The requests appear to come from real browsers with valid headers. Which tool is most likely being used, and which countermeasure would be most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.