Courseiva

CEH Practice Question: Malware, Social Engineering and Network Attacks

Which THREE of the following are common methods used to mitigate DDoS attacks? (Select 3)

⚠ Common exam trap

EC-CEH often tests the distinction between attack techniques (like MAC flooding and ARP poisoning) and legitimate mitigation strategies, so candidates mistakenly select these as defenses because they are network-related terms.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Rate limiting

Rate limiting (B) is correct because it caps the number of requests or packets a client or service can send per unit time, so volumetric floods and application-layer floods are throttled before they exhaust server or bandwidth resources. Scrubbing centers (C) are correct because they divert incoming traffic to specialized cleaning facilities that filter out malicious DDoS packets via signature, anomaly, and behavioral analysis and forward only legitimate traffic to the origin. Anycast network distribution (E) is correct because advertising the same IP prefix from many geographically dispersed points of presence spreads attack traffic across the provider's global edge, absorbing and dispersing volumetric floods while bringing legitimate users to the nearest node. MAC flooding (A) is not a mitigation but a Layer 2 switch attack that overflows the CAM table to force hub-like flooding, and ARP poisoning (D) is a Layer 2 man-in-the-middle attack that forges ARP replies to associate an attacker's MAC with a victim's IP, so neither belongs among DDoS mitigation methods.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    MAC flooding

    Why it's wrong here

    MAC flooding exhausts a switch's CAM table to force hub-like flooding; it is an attack, not a DDoS mitigation. It is tempting because it targets network infrastructure and degrades availability, so it would be the correct answer if the question asked which attack causes denial of service on a local segment.

  • ✓

    Rate limiting

    Why this is correct

    Rate limiting caps the volume of requests a server or network accepts per source within a defined window, absorbing volumetric floods before they exhaust bandwidth or processing capacity. This directly satisfies the stem's mitigation requirement by throttling malicious traffic while permitting legitimate connections, a standard DDoS defence alongside traffic filtering and content delivery networks.

  • ✓

    Scrubbing centers

    Why this is correct

    Scrubbing centres divert inbound traffic through dedicated filtering appliances that strip volumetric and protocol floods before clean traffic is forwarded to the origin, satisfying the need to absorb attack bandwidth away from protected infrastructure. This centralised diversion and cleaning mechanism directly mitigates DDoS by preventing saturation of the target's links and servers.

  • ✗

    ARP poisoning

    Why it's wrong here

    ARP poisoning is an attack that redirects LAN traffic by forging ARP replies; it mitigates nothing and is itself a man-in-the-middle technique. It is tempting because it manipulates network traffic, so it would be the correct answer if the question asked which technique enables traffic interception rather than which mitigates DDoS.

  • ✓

    Anycast network distribution

    Why this is correct

    Anycast advertises one IP from many locations, so BGP routes each user to the nearest node. Attack traffic is thereby dispersed across the provider's global edge rather than converging on a single host, absorbing volumetric floods. This directly satisfies the stem's mitigation requirement by preventing traffic concentration, the mechanism that makes DDoS effective.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.