CS0-003 Incident Response and Management Practice Question
An organization is experiencing a DDoS attack targeting its web servers. Which of the following is the BEST short-term containment strategy?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reroute traffic through a DDoS mitigation service.
Short-term containment for DDoS often involves rerouting traffic through a scrubbing center or cloud-based DDoS mitigation service that filters malicious traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Rebuild the web servers from backups.
Why it's wrong here
Rebuilding web servers from backups is an incident recovery step used to remediate malware infections or system corruption. It does not address the external network-layer or application-layer traffic flooding the infrastructure, and the newly rebuilt servers would immediately be overwhelmed by the ongoing DDoS attack.
- ✗
Implement rate limiting on the firewall.
Why it's wrong here
While rate limiting on a local firewall can restrict the volume of requests, it often lacks the granularity to distinguish between malicious botnet traffic and legitimate user requests. Furthermore, the firewall's state table and internet uplink bandwidth can still be completely saturated by a volumetric DDoS attack before the rate limits are even applied.
- ✓
Reroute traffic through a DDoS mitigation service.
Why this is correct
Rerouting traffic to a cloud-based DDoS mitigation or scrubbing service (via DNS or BGP redirection) is the most effective containment strategy. This allows the provider to filter out malicious traffic at the network edge using global scrubbing centers, ensuring that only clean, legitimate traffic reaches the organization's origin servers.
- ✗
Disable the web server accounts.
Why it's wrong here
Disabling web server user or service accounts is an access control containment measure used during credential stuffing or unauthorized access incidents. It is ineffective against a DDoS attack, which targets network bandwidth, system resources, or application availability rather than exploiting compromised user credentials.
Visual reference
Go deeper
Related to this question
Learn chapter
Cloud Security Posture Management (CSPM)
Key term
Containment
Containment is the incident response phase where security teams isolate a compromised system or network to prevent the threat from spreading further while preserving evidence.
Key term
Mitigation
Mitigation is the process of reducing the severity, impact, or likelihood of a security threat or vulnerability.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.