
EC-CouncilEthical Hacking Essentials
Domain 5Objective 2
DoS and DDoS Attack Methods EHE Practice Questions (Page 4)
Part of the Network-Level Attacks and Countermeasures domain, which makes up ~12% of our current practice bank.
63questions here
13free pages
17concepts
Questions 16–20
- 16
A gaming company's authoritative DNS servers are overwhelmed by a flood of large DNS responses. The responses are coming from many unrelated public DNS servers, and the queries appear to be for a single domain with a large TXT record. The company's own DNS servers are not the source. What is the most likely attack and the best immediate mitigation?
Select an answer first - 17
A small e-commerce company's web server becomes unresponsive. The administrator checks the server and finds thousands of half-open TCP connections in the SYN_RECEIVED state, consuming the connection table. The source IPs appear randomized. Which immediate mitigation is most effective while preserving legitimate access?
Select an answer first - 18
A news website is experiencing slow response times. The web server logs show many connections that send partial HTTP headers and then remain idle, tying up worker threads. The source IPs are numerous and appear to be from a botnet. The traffic volume is low, and bandwidth is not saturated. Which countermeasure would be most effective?
Select an answer first - 19
An online retailer's application server becomes slow during a marketing campaign. The server logs show a high volume of legitimate-looking GET requests for the product catalog page, each from a different IP address. The requests are not malformed, and the server's CPU is pegged. The network bandwidth is not saturated. Which mitigation is most appropriate?
Select an answer first - 20
What is the key mechanism behind a DNS amplification attack?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.