CEH Practice Question: Malware, Social Engineering and Network Attacks
A company's security team wants to deploy a DDoS mitigation technique that distributes incoming traffic across multiple servers in different geographic locations, making it harder for an attacker to overwhelm a single target. Which technique BEST fits this description?
⚠ Common exam trap
EC-CEH candidates often mistake a load balancer for anycast networking. While a load balancer distributes traffic among servers, it does not inherently provide geographic distribution via BGP path selection, which is the key differentiator for absorbing volumetric DDoS attacks at scale.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Anycast network
Anycast network routing allows the same IP address to be advertised from multiple geographically distributed servers. When traffic arrives, BGP (Border Gateway Protocol) automatically directs each packet to the nearest or best-path server, effectively spreading the load and absorbing volumetric DDoS attacks by preventing any single server from becoming a bottleneck.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Anycast network
Why this is correct
Anycast advertises one IP address from many points of presence, so routing protocols steer each user to the topologically nearest server. Traffic is thereby dispersed across geographically distributed servers, preventing an attacker from concentrating volume on a single target.
- ✗
Rate limiting
Why it's wrong here
Rate limiting caps requests per client or connection, throttling volume at a single ingress point; it does not spread traffic across servers in multiple geographic locations. It is tempting because it blunts volumetric floods, and would be correct for limiting API abuse or brute-force attempts against one endpoint.
- ✗
Load balancer
Why it's wrong here
A load balancer distributes traffic across servers, but standard load balancing typically operates within one region or data centre rather than across multiple geographic locations. It is tempting because it spreads load, and would be correct for horizontal scaling within a single site.
- ✗
Scrubbing center
Why it's wrong here
A scrubbing centre diverts and cleans malicious traffic centrally before forwarding legitimate packets, concentrating rather than geographically distributing traffic across servers. It is tempting because it absorbs volumetric attacks, and would be correct for filtering large-scale DDoS floods away from origin infrastructure.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.