Courseiva

CS0-003 Incident Response and Management Practice Question

An organization is experiencing a DDoS attack targeting its web servers. Which of the following is the BEST short-term containment strategy?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reroute traffic through a DDoS mitigation service.

Short-term containment for DDoS often involves rerouting traffic through a scrubbing center or cloud-based DDoS mitigation service that filters malicious traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Rebuild the web servers from backups.

    Why it's wrong here

    Rebuilding web servers from backups is an incident recovery step used to remediate malware infections or system corruption. It does not address the external network-layer or application-layer traffic flooding the infrastructure, and the newly rebuilt servers would immediately be overwhelmed by the ongoing DDoS attack.

  • ✗

    Implement rate limiting on the firewall.

    Why it's wrong here

    While rate limiting on a local firewall can restrict the volume of requests, it often lacks the granularity to distinguish between malicious botnet traffic and legitimate user requests. Furthermore, the firewall's state table and internet uplink bandwidth can still be completely saturated by a volumetric DDoS attack before the rate limits are even applied.

  • ✓

    Reroute traffic through a DDoS mitigation service.

    Why this is correct

    Rerouting traffic to a cloud-based DDoS mitigation or scrubbing service (via DNS or BGP redirection) is the most effective containment strategy. This allows the provider to filter out malicious traffic at the network edge using global scrubbing centers, ensuring that only clean, legitimate traffic reaches the organization's origin servers.

  • ✗

    Disable the web server accounts.

    Why it's wrong here

    Disabling web server user or service accounts is an access control containment measure used during credential stuffing or unauthorized access incidents. It is ineffective against a DDoS attack, which targets network bandwidth, system resources, or application availability rather than exploiting compromised user credentials.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.