Courseiva

CEH Practice Question: Malware, Social Engineering and Network Attacks

An organization is experiencing repeated DDoS attacks that consume all available bandwidth. Which mitigation technique is MOST effective for handling such volumetric attacks?

⚠ Common exam trap

A common mistake is to assume that anycast distribution (Option B) mitigates volumetric attacks by spreading traffic across servers. However, anycast only distributes the load; it does not filter malicious traffic. Volumetric attacks require actual traffic scrubbing to remove malicious data, which is provided by scrubbing centers (Option D).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Scrubbing centers

Scrubbing centers (Option D) are the most effective mitigation for volumetric DDoS attacks because they use specialized hardware and software to filter malicious traffic from legitimate traffic before it reaches the target network. Unlike simpler methods, scrubbing centers can handle massive bandwidth floods by redirecting traffic through high-capacity filtering nodes that inspect packets, drop attack traffic based on signatures or behavioral analysis, and forward only clean traffic. This approach is specifically designed for volumetric attacks that saturate bandwidth, as it offloads the filtering burden from the target's own infrastructure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Blackholing all traffic to the target IP

    Why it's wrong here

    Blackholing drops all traffic to the target, including legitimate users, so it sacrifices availability rather than filtering attack traffic. It is tempting as an emergency stop, and it would be correct where the target is non-critical and preserving service is not required.

  • ✗

    Anycast network distribution

    Why it's wrong here

    Anycast distributes traffic across multiple nodes sharing one IP, which absorbs some load but does not stop a volumetric flood exhausting each upstream link. It is designed for latency reduction and resilience, so it would suit globally distributed services needing faster routing, not bandwidth-saturation defence.

  • ✗

    Rate limiting on the firewall

    Why it's wrong here

    Firewall rate limiting caps connections per source, which does little against distributed volumetric floods saturating the link from many sources. It is tempting because rate limiting handles single-source abuse, and it would be correct for throttling excessive requests from identifiable clients rather than bandwidth exhaustion.

  • ✓

    Scrubbing centers

    Why this is correct

    Scrubbing centres divert incoming traffic to dedicated facilities that filter and clean malicious volumetric floods before forwarding legitimate packets, absorbing the bandwidth-saturating load upstream. This preserves the organisation's own internet link, which on-premises filtering cannot achieve during a bandwidth-exhaustion attack.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.