CEH Practice Question: Malware, Social Engineering and Network Attacks
An organization is experiencing repeated DDoS attacks that consume all available bandwidth. Which mitigation technique is MOST effective for handling such volumetric attacks?
⚠ Common exam trap
A common mistake is to assume that anycast distribution (Option B) mitigates volumetric attacks by spreading traffic across servers. However, anycast only distributes the load; it does not filter malicious traffic. Volumetric attacks require actual traffic scrubbing to remove malicious data, which is provided by scrubbing centers (Option D).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Scrubbing centers
Scrubbing centers (Option D) are the most effective mitigation for volumetric DDoS attacks because they use specialized hardware and software to filter malicious traffic from legitimate traffic before it reaches the target network. Unlike simpler methods, scrubbing centers can handle massive bandwidth floods by redirecting traffic through high-capacity filtering nodes that inspect packets, drop attack traffic based on signatures or behavioral analysis, and forward only clean traffic. This approach is specifically designed for volumetric attacks that saturate bandwidth, as it offloads the filtering burden from the target's own infrastructure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Blackholing all traffic to the target IP
Why it's wrong here
Blackholing drops all traffic to the target, including legitimate users, so it sacrifices availability rather than filtering attack traffic. It is tempting as an emergency stop, and it would be correct where the target is non-critical and preserving service is not required.
- ✗
Anycast network distribution
Why it's wrong here
Anycast distributes traffic across multiple nodes sharing one IP, which absorbs some load but does not stop a volumetric flood exhausting each upstream link. It is designed for latency reduction and resilience, so it would suit globally distributed services needing faster routing, not bandwidth-saturation defence.
- ✗
Rate limiting on the firewall
Why it's wrong here
Firewall rate limiting caps connections per source, which does little against distributed volumetric floods saturating the link from many sources. It is tempting because rate limiting handles single-source abuse, and it would be correct for throttling excessive requests from identifiable clients rather than bandwidth exhaustion.
- ✓
Scrubbing centers
Why this is correct
Scrubbing centres divert incoming traffic to dedicated facilities that filter and clean malicious volumetric floods before forwarding legitimate packets, absorbing the bandwidth-saturating load upstream. This preserves the organisation's own internet link, which on-premises filtering cannot achieve during a bandwidth-exhaustion attack.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.