Courseiva

Application-Layer DDoS Attacks: Slowloris and HTTP Flood

Which TWO of the following are examples of application-layer DDoS attacks? (Choose two.)

Quick Answer

The correct answer is HTTP flood, along with Slowloris, as both are classic examples of application-layer DDoS attacks. These attacks target Layer 7 of the OSI model, where they exhaust server resources by mimicking legitimate user requests—HTTP flood overwhelms a server with seemingly valid GET or POST requests, while Slowloris opens many connections and keeps them hanging by sending partial headers. On the Certified Ethical Hacker CEH exam, this distinction tests your ability to classify attacks by OSI layer; a common trap is confusing application-layer attacks with protocol or volumetric ones, such as SYN flood (Layer 4) or UDP flood (Layer 3). To remember, think of the “application” layer as the one closest to the user—attacks here look like normal traffic but are designed to tie up server threads or fill connection pools. A useful memory tip: “Slow and HTTP both speak HTTP,” meaning they operate at the application layer where HTTP lives, unlike SYN or Smurf which abuse lower-level protocols.

⚠ Common exam trap

Candidates often confuse transport-layer attacks (like SYN floods and UDP floods) with application-layer attacks, because both can cause denial of service, but only application-layer attacks target specific protocols like HTTP, DNS, or SMTP at Layer 7.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Slowloris

Slowloris (B) is an application-layer DDoS attack because it opens many partial HTTP connections to a web server and keeps them alive by sending incomplete headers, exhausting the server's connection pool at Layer 7. HTTP flood (C) is also an application-layer attack because it overwhelms a web application with seemingly legitimate HTTP GET or POST requests, consuming server and application resources. By contrast, UDP flood (A) is a volumetric transport/network-layer attack that saturates bandwidth with UDP packets, SYN flood (D) exploits the TCP three-way handshake at the transport layer by leaving half-open connections, and Smurf attack (E) is an ICMP-based network-layer amplification attack using broadcast addresses.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    UDP flood

    Why it's wrong here

    A UDP flood saturates bandwidth and transport-layer ports with datagrams, involving no application protocol parsing. It is tempting because UDP underpins DNS and QUIC, yet the flood itself is transport-layer. It would be correct if the question asked for network-layer volumetric attacks.

  • ✓

    Slowloris

    Why this is correct

    Slowloris exhausts a web server's connection pool by opening many partial HTTP requests and holding them open, sending periodic header fragments to prevent timeouts. Operating at the application layer, it satisfies the stem's requirement by targeting HTTP rather than network or transport resources, unlike volumetric or SYN-flood techniques.

  • ✓

    HTTP flood

    Why this is correct

    An HTTP flood exhausts a target by sending seemingly legitimate GET or POST requests, operating at layer 7 where it consumes web server and application resources rather than raw bandwidth. This satisfies the stem's application-layer constraint, distinguishing it from volumetric network-layer attacks such as UDP or SYN floods.

  • ✗

    SYN flood

    Why it's wrong here

    A SYN flood exhausts TCP connection state in the transport layer by withholding final ACKs; it never reaches HTTP or DNS parsing. It is tempting because it is the classic volumetric DoS example, and would be the right answer if the question asked about network- or transport-layer attacks.

  • ✗

    Smurf attack

    Why it's wrong here

    A Smurf attack spoofs ICMP echo requests to a broadcast address, amplifying traffic at the network layer; ICMP carries no application payload. It is tempting as a well-known amplification technique, and would be correct if the question asked about network-layer reflection or amplification attacks.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

7 more ways this is tested on CEH

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO of the following are examples of application layer (Layer 7) DDoS attacks? (Select 2)

medium
  • ✓ A.HTTP flood
  • B.Smurf attack
  • C.SYN flood
  • D.UDP flood
  • ✓ E.Slowloris

Why A: HTTP flood is a Layer 7 DDoS attack because it targets the application layer by sending seemingly legitimate HTTP GET or POST requests to overwhelm a web server's resources. Unlike network-layer attacks, HTTP flood exploits the server's ability to process requests, often mimicking normal user behavior to bypass basic rate limiting. Slowloris is also a Layer 7 attack that works by opening multiple HTTP connections and keeping them open with partial requests, exhausting the server's connection pool without completing the handshake.

Variation 2. Which TWO of the following are examples of application-layer DDoS attacks? (Select 2)

medium
  • ✓ A.HTTP flood
  • B.ICMP flood
  • C.SYN flood
  • D.UDP flood
  • ✓ E.Slowloris

Why A: HTTP flood (A) is an application-layer (Layer 7) DDoS attack because it sends massive volumes of seemingly legitimate HTTP GET or POST requests to exhaust a web server's resources, such as worker threads, database connections, or CPU. Slowloris (E) is also an application-layer attack: it opens many partial HTTP connections and sends incomplete headers slowly, keeping sockets open and tying up the web server's connection pool without ever completing a request. By contrast, ICMP flood (B) operates at the network layer (Layer 3) using ICMP echo requests, SYN flood (C) targets the transport layer (Layer 4) by abusing the TCP three-way handshake with half-open connections, and UDP flood (D) is a transport/network-layer volumetric attack that saturates bandwidth with UDP datagrams — none of these three are application-layer attacks.

Variation 3. Which TWO of the following are examples of application-layer DDoS attacks? (Select 2)

medium
  • A.UDP flood
  • ✓ B.HTTP flood
  • ✓ C.Slowloris
  • D.ICMP flood
  • E.SYN flood

Why B: HTTP flood (B) is correct because it operates at the application layer (Layer 7), overwhelming a web server with seemingly legitimate HTTP GET or POST requests that consume server resources and bandwidth. Slowloris (C) is also correct because it is a Layer 7 attack that opens many partial HTTP connections and sends incomplete headers, keeping sockets open and exhausting the web server's connection pool without needing high bandwidth. UDP flood (A) is incorrect because it is a volumetric transport-layer (Layer 4) attack that sends large numbers of UDP packets to random ports. ICMP flood (D) is incorrect because it is a network-layer (Layer 3) attack using ICMP echo requests. SYN flood (E) is incorrect because it exploits the TCP handshake at the transport layer (Layer 4) by sending many SYN packets without completing the connection.

Variation 4. Which TWO of the following are examples of application-layer DDoS attacks? (Select 2)

medium
  • ✓ A.Slowloris
  • B.SYN flood
  • C.Smurf attack
  • D.UDP flood
  • ✓ E.HTTP flood

Why A: Slowloris (A) is an application-layer (Layer 7) DDoS attack because it opens many partial HTTP connections to a web server and keeps them alive by sending incomplete request headers, exhausting the server's connection pool without ever completing a request. HTTP flood (E) is also an application-layer attack because it sends a high volume of seemingly legitimate HTTP GET or POST requests that consume server, application, and database resources. Both target the application/HTTP protocol rather than the network or transport layers. By contrast, SYN flood (B) exploits the TCP three-way handshake at the transport layer, Smurf attack (C) abuses ICMP echo requests with a spoofed source address at the network layer, and UDP flood (D) overwhelms a target with UDP packets at the transport layer, so none of these are application-layer attacks.

Variation 5. Which TWO of the following are examples of application layer DDoS attacks? (Select two.)

medium
  • ✓ A.Slowloris
  • B.UDP flood
  • C.Smurf attack
  • ✓ D.HTTP flood
  • E.SYN flood

Why A: Slowloris (A) is an application-layer (Layer 7) DDoS attack because it opens many partial HTTP connections and sends incomplete request headers, exhausting the web server's connection pool without ever completing a request. HTTP flood (D) is also an application-layer attack, since it overwhelms a web server with seemingly legitimate HTTP GET or POST requests that consume CPU, memory, and application resources. By contrast, UDP flood (B) is a volumetric transport/network-layer attack that saturates bandwidth with User Datagram Protocol packets. Smurf attack (C) is an ICMP-based network-layer amplification attack using broadcast addresses and spoofed source IPs. SYN flood (E) is a transport-layer attack that exploits the TCP three-way handshake by leaving half-open connections, not an application-layer attack.

Variation 6. Which THREE of the following are examples of application-layer DDoS attacks? (Select 3)

hard
  • ✓ A.Slowloris
  • ✓ B.HTTP flood
  • C.SYN flood
  • ✓ D.DNS amplification
  • E.UDP flood

Why A: Slowloris (A) is an application-layer DDoS attack because it opens many partial HTTP connections and holds them open with incomplete headers, exhausting the web server's connection pool at Layer 7. HTTP flood (B) is also application-layer, as it sends seemingly legitimate HTTP GET or POST requests to overwhelm a web application or API rather than the network stack. DNS amplification (D) is an application-layer attack because it abuses DNS queries (UDP/53) with spoofed source addresses to generate large responses toward the victim, magnifying traffic at the application protocol level. By contrast, SYN flood (C) is a transport-layer attack exploiting the TCP three-way handshake, and UDP flood (E) is a transport/network-layer volumetric attack, so neither belongs in the application-layer category.

Variation 7. Which TWO of the following are examples of application-layer DDoS attacks?

medium
  • A.ICMP flood
  • ✓ B.Slowloris
  • C.SYN flood
  • ✓ D.HTTP flood
  • E.UDP flood

Why B: Slowloris (B) is an application-layer DDoS attack because it operates at Layer 7 by opening many partial HTTP connections and sending incomplete request headers, exhausting the web server's connection pool without ever completing a request. HTTP flood (D) is also an application-layer attack, since it overwhelms a web server with a high volume of seemingly legitimate HTTP GET or POST requests that consume CPU, memory, and application resources. In contrast, ICMP flood (A), SYN flood (C), and UDP flood (E) are network- or transport-layer attacks: ICMP and UDP floods simply blast packets at Layers 3/4, and a SYN flood exploits the TCP three-way handshake at Layer 4, so none of them target application-layer protocols like HTTP.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.