Courseiva

CEH Practice Question: Malware, Social Engineering and Network Attacks

Which TWO of the following are effective mitigation techniques against DDoS attacks? (Select two)

⚠ Common exam trap

In the CEH exam, it's important to distinguish between 'preventive controls' (like port knocking or MAC filtering) and 'mitigative controls' (like rate limiting and scrubbing centers). Candidates often mistakenly select port knocking as a DDoS defense because they confuse access control with traffic management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Rate limiting

Rate limiting (C) is correct because it caps the number of requests or packets a client or subnet can send per unit time (e.g., via iptables hashlimit, nginx limit_req, or cloud WAF throttling rules), which blunts volumetric and application-layer floods by preventing any single source from exhausting server or bandwidth resources. Scrubbing centers (D) are correct because they are dedicated, high-capacity traffic-cleaning facilities that divert attack traffic via BGP anycast or GRE tunnels, filter out malicious packets using signature, anomaly, and reputation analysis, and forward only legitimate traffic back to the origin. Port knocking (A) is not a DDoS mitigation; it is a stealth access-control mechanism that hides services behind a sequence of connection attempts and does nothing to absorb or filter high-volume attack traffic. ARP poisoning (B) is itself an attack (Layer 2 man-in-the-middle via forged ARP replies), not a defense. MAC filtering (E) is a Layer 2 access-control list that restricts which hardware addresses can associate with a switch or AP, and it is trivially bypassed by spoofing and irrelevant to mitigating distributed floods.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Port knocking

    Why it's wrong here

    Port knocking is a network access control mechanism where a user attempts to connect to a series of closed ports in a specific, predefined sequence to open a single, otherwise closed, port on the firewall. This technique is primarily used for stealthy remote access and authentication, not for filtering or absorbing the high volumes of malicious traffic characteristic of a Distributed Denial of Service (DDoS) attack. It does not prevent the initial flood of packets from reaching the network perimeter.

  • ✗

    ARP poisoning

    Why it's wrong here

    ARP poisoning, also known as ARP spoofing, is a malicious technique where an attacker sends falsified Address Resolution Protocol (ARP) messages over a local area network. This links an attacker's MAC address with the IP address of a legitimate network device, such as a router or another host, to intercept or modify traffic. As an offensive technique used to disrupt or eavesdrop on network communications, it is fundamentally an attack vector, not a defensive mitigation strategy against DDoS attacks.

  • ✓

    Rate limiting

    Why this is correct

    Rate limiting is an effective DDoS mitigation technique that controls the amount of incoming or outgoing traffic a network, server, or application can handle within a specific timeframe. By setting thresholds on the number of requests, connections, or packets allowed from a particular source IP address or to a specific resource, it prevents a single entity or a distributed group of attackers from overwhelming the target with excessive traffic. This helps maintain service availability by dropping requests that exceed the defined limits.

  • ✓

    Scrubbing centers

    Why this is correct

    Scrubbing centers are specialized, high-capacity data centers designed to analyze and filter out malicious traffic, particularly during large-scale Distributed Denial of Service (DDoS) attacks. When an attack is detected, incoming traffic is rerouted through these centers, where advanced filtering technologies identify and remove attack packets while allowing legitimate traffic to proceed to the intended destination. This offloads the attack burden from the target's infrastructure, ensuring business continuity and service availability.

  • ✗

    MAC filtering

    Why it's wrong here

    MAC filtering is a Layer 2 access control method that permits or denies network access based on a device's unique Media Access Control (MAC) address. While it can be used for basic access control on small, static networks, it is easily bypassed by MAC spoofing and is entirely ineffective against Distributed Denial of Service (DDoS) attacks. DDoS attacks typically involve a vast number of spoofed or legitimate, but compromised, IP addresses and operate at higher network layers, rendering MAC-based filtering irrelevant for large-scale volumetric attacks.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.