Courseiva

CEH Practice Question: Malware, Social Engineering and Network Attacks

Which THREE of the following are effective DDoS mitigation techniques?

⚠ Common exam trap

The CEH exam often tests the misconception that IP blacklisting is a viable DDoS mitigation technique, but candidates must remember that blacklisting is ineffective against distributed, spoofed-source attacks where the attacker can easily change IP addresses.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Scrubbing centers

Scrubbing centers (C) are correct because they divert and filter malicious traffic through specialized cleaning appliances before forwarding only legitimate traffic to the origin, which is a core DDoS mitigation strategy. Rate limiting (D) is correct because it caps the number of requests or connections per source or service, preventing volumetric and application-layer floods from overwhelming resources. Anycast routing (E) is correct because it distributes traffic across multiple geographically dispersed nodes sharing the same IP, dispersing attack volume and enabling closer filtering and absorption. IP blacklisting (A) is not effective as a primary DDoS mitigation because attackers spoof or rotate source IPs, making blocklists trivial to bypass. Increasing server resources (B) only raises the attack threshold temporarily and does not stop the flood, so it is not a true mitigation technique.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    IP blacklisting

    Why it's wrong here

    IP blacklisting is largely ineffective against modern Distributed Denial of Service (DDoS) attacks because attackers frequently employ IP spoofing, forging source IP addresses to evade detection and attribution. Furthermore, the sheer volume and dynamic nature of botnet-driven attacks mean that malicious traffic can originate from thousands or even millions of constantly changing, legitimate-looking IP addresses, making manual or automated blacklisting an unmanageable and futile effort.

  • ✗

    Increasing server resources

    Why it's wrong here

    While adding more server capacity, such as CPU, RAM, or bandwidth, might temporarily absorb a small-scale DDoS attack, it is not a sustainable primary mitigation strategy. Attackers can easily scale their botnet resources to overwhelm any incremental increase in target infrastructure, turning it into an expensive and ultimately losing arms race. Effective DDoS mitigation requires proactive traffic management and filtering, not just reactive resource scaling.

  • ✓

    Scrubbing centers

    Why this is correct

    Scrubbing centers are specialized, high-capacity network infrastructures designed to filter and clean malicious traffic before it reaches the protected target. These centers ingest all incoming traffic, analyze it for known attack patterns and anomalies across various layers, and then forward only the legitimate, clean traffic to the origin server. This offloads the attack burden from the target's infrastructure, ensuring service continuity.

  • ✓

    Rate limiting

    Why this is correct

    Rate limiting is a crucial DDoS mitigation technique that restricts the number of requests or connections allowed from a specific source IP address or to a particular service within a defined timeframe. By imposing thresholds on incoming traffic, it prevents a single attacker or a distributed attack from overwhelming server resources, network bandwidth, or application processes. This helps maintain service availability for legitimate users by dropping or delaying excessive requests.

  • ✓

    Anycast routing

    Why this is correct

    Anycast routing significantly enhances DDoS resilience by advertising the same IP address from multiple geographically distributed server instances. When a client or attacker attempts to connect, network routing protocols direct the traffic to the topologically nearest available server. This architecture effectively distributes and dilutes the impact of a large-scale attack across numerous endpoints, preventing any single server from becoming a bottleneck or single point of failure.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This CEH question is part of Courseiva's 913-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.