Courseiva

CEH Practice Question: Malware, Social Engineering and Network Attacks

A company's security team wants to deploy a DDoS mitigation technique that distributes incoming traffic across multiple servers in different geographic locations, making it harder for an attacker to overwhelm a single target. Which technique BEST fits this description?

⚠ Common exam trap

EC-CEH candidates often mistake a load balancer for anycast networking. While a load balancer distributes traffic among servers, it does not inherently provide geographic distribution via BGP path selection, which is the key differentiator for absorbing volumetric DDoS attacks at scale.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Anycast network

Anycast network routing allows the same IP address to be advertised from multiple geographically distributed servers. When traffic arrives, BGP (Border Gateway Protocol) automatically directs each packet to the nearest or best-path server, effectively spreading the load and absorbing volumetric DDoS attacks by preventing any single server from becoming a bottleneck.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Anycast network

    Why this is correct

    Anycast advertises one IP address from many points of presence, so routing protocols steer each user to the topologically nearest server. Traffic is thereby dispersed across geographically distributed servers, preventing an attacker from concentrating volume on a single target.

  • ✗

    Rate limiting

    Why it's wrong here

    Rate limiting caps requests per client or connection, throttling volume at a single ingress point; it does not spread traffic across servers in multiple geographic locations. It is tempting because it blunts volumetric floods, and would be correct for limiting API abuse or brute-force attempts against one endpoint.

  • ✗

    Load balancer

    Why it's wrong here

    A load balancer distributes traffic across servers, but standard load balancing typically operates within one region or data centre rather than across multiple geographic locations. It is tempting because it spreads load, and would be correct for horizontal scaling within a single site.

  • ✗

    Scrubbing center

    Why it's wrong here

    A scrubbing centre diverts and cleans malicious traffic centrally before forwarding legitimate packets, concentrating rather than geographically distributing traffic across servers. It is tempting because it absorbs volumetric attacks, and would be correct for filtering large-scale DDoS floods away from origin infrastructure.

About these practice questions

Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.