
EC-CouncilCertified Ethical Hacker
Domain 4Objective 3
Denial-of-Service and DDoS CEH Practice Questions (Page 9)
Part of the Network and Perimeter Hacking domain, which makes up ~9% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~9–14 in this domain), expect 2–3 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
6concepts
Questions 41–45
- 41
A company's website is under an HTTP flood attack. The attack traffic appears to come from many different IP addresses, and each request asks for a different URL that returns a 404 error. The company's web server logs show a high rate of 404 responses. Which mitigation technique would be most effective in this scenario?
Select an answer first - 42
A company's network is under a DDoS attack that is saturating the internet link. The company has a firewall that can filter traffic based on IP addresses and ports. Which immediate action is most likely to reduce the impact of the attack?
Select an answer first - 43
What is the primary purpose of 'stress-testing' tools in the context of DDoS?
Select an answer first - 44
Which type of DDoS attack is characterized by overwhelming a target with a massive volume of traffic, such as UDP floods?
Select an answer first - 45
A security analyst notices that a large number of IoT devices on the internet are sending traffic to a single IP address. The traffic consists of small UDP packets to port 53, and the source IPs are spoofed to be the target's IP. The analyst suspects a DDoS attack is being launched using these devices. What is the most accurate description of this attack?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.