
EC-CouncilEthical Hacking Essentials
Domain 5Objective 2
DoS and DDoS Attack Methods EHE Practice Questions (Page 9)
Part of the Network-Level Attacks and Countermeasures domain, which makes up ~12% of our current practice bank.
63questions here
13free pages
17concepts
Questions 41–45
- 41
An online booking system becomes unresponsive during a promotional campaign. The web server logs show a high number of POST requests to the booking endpoint, each from a different IP address, with complete TCP handshakes. The server's CPU usage is high, but network bandwidth is normal. Which mitigation is most appropriate?
Select an answer first - 42
Which of the following is an effective countermeasure to reduce the impact of a DDoS attack?
Select an answer first - 43
A company's application server is experiencing slow responses during peak hours. The administrator suspects an application-layer DDoS attack, but the traffic appears to be legitimate HTTP requests from many different IPs. The requests are for a search endpoint that is CPU-intensive. The company has a CDN, but the CDN is not filtering the traffic. What is the most effective way to mitigate the attack while minimizing impact on legitimate users?
Select an answer first - 44
Which protocol is exploited in an ICMP flood attack?
Select an answer first - 45
A company's firewall is overwhelmed by a flood of TCP SYN packets to a single server. The administrator has enabled SYN cookies on the server, but the firewall itself is now the bottleneck because it is processing a high volume of packets. What is the most effective way to protect the firewall and the server?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.