Courseiva

CEH Rate Limiting Practice Question

Which of the following is the BEST defense against brute-force attacks on a login form?

⚠ Common exam trap

The question uses the word 'BEST' to indicate a single correct answer. Do not assume multiple answers are correct. Account lockout is the most direct defense because it halts repeated failed attempts against the targeted account, while rate limiting can be evaded via distributed or low-rate attacks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Account lockout after 5 failed attempts

Account lockout after a small number of failed attempts (D) is the most direct and effective defense against brute-force attacks on a login form: it stops the attack at the source by disabling the targeted account after repeated failures, regardless of source IP. Rate limiting (A) is a useful complementary control, but it can be bypassed by distributing attempts across many IPs and does not stop slow, low-rate brute-force attempts. CAPTCHA (B) can be bypassed by automated solvers, and complex password policies (C) do not prevent repeated attempts. Therefore the BEST answer is D.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Rate limiting on the login endpoint

    Why it's wrong here

    Rate limiting directly limits the rate of login attempts, effectively preventing brute-force attacks by throttling requests regardless of IP. It is proactive and difficult to bypass, making it the best defense.

  • ✗

    CAPTCHA

    Why it's wrong here

    CAPTCHA can slow down automated attacks but is often bypassed using CAPTCHA-solving services. It is less robust than rate limiting and degrades user experience, so it is not the best.

  • ✗

    Complex password policy

    Why it's wrong here

    Complex password policy makes passwords harder to guess but does not prevent repeated attempts. It is a passive defense and not the best against brute-force.

  • ✓

    Account lockout after 5 failed attempts

    Why this is correct

    Account lockout after 5 failed attempts can be circumvented by distributed attacks from many IPs. It is reactive and may cause denial of service for legitimate users, so it is not the best.

About these practice questions

This CEH question is part of Courseiva's 913-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.