CEH Practice Question: Malware, Social Engineering and Network Attacks
Which TWO of the following are effective mitigation techniques against DDoS attacks? (Select two)
⚠ Common exam trap
In the CEH exam, it's important to distinguish between 'preventive controls' (like port knocking or MAC filtering) and 'mitigative controls' (like rate limiting and scrubbing centers). Candidates often mistakenly select port knocking as a DDoS defense because they confuse access control with traffic management.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Rate limiting
Rate limiting (C) is correct because it caps the number of requests or packets a client or subnet can send per unit time (e.g., via iptables hashlimit, nginx limit_req, or cloud WAF throttling rules), which blunts volumetric and application-layer floods by preventing any single source from exhausting server or bandwidth resources. Scrubbing centers (D) are correct because they are dedicated, high-capacity traffic-cleaning facilities that divert attack traffic via BGP anycast or GRE tunnels, filter out malicious packets using signature, anomaly, and reputation analysis, and forward only legitimate traffic back to the origin. Port knocking (A) is not a DDoS mitigation; it is a stealth access-control mechanism that hides services behind a sequence of connection attempts and does nothing to absorb or filter high-volume attack traffic. ARP poisoning (B) is itself an attack (Layer 2 man-in-the-middle via forged ARP replies), not a defense. MAC filtering (E) is a Layer 2 access-control list that restricts which hardware addresses can associate with a switch or AP, and it is trivially bypassed by spoofing and irrelevant to mitigating distributed floods.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Port knocking
Why it's wrong here
Port knocking is a network access control mechanism where a user attempts to connect to a series of closed ports in a specific, predefined sequence to open a single, otherwise closed, port on the firewall. This technique is primarily used for stealthy remote access and authentication, not for filtering or absorbing the high volumes of malicious traffic characteristic of a Distributed Denial of Service (DDoS) attack. It does not prevent the initial flood of packets from reaching the network perimeter.
- ✗
ARP poisoning
Why it's wrong here
ARP poisoning, also known as ARP spoofing, is a malicious technique where an attacker sends falsified Address Resolution Protocol (ARP) messages over a local area network. This links an attacker's MAC address with the IP address of a legitimate network device, such as a router or another host, to intercept or modify traffic. As an offensive technique used to disrupt or eavesdrop on network communications, it is fundamentally an attack vector, not a defensive mitigation strategy against DDoS attacks.
- ✓
Rate limiting
Why this is correct
Rate limiting is an effective DDoS mitigation technique that controls the amount of incoming or outgoing traffic a network, server, or application can handle within a specific timeframe. By setting thresholds on the number of requests, connections, or packets allowed from a particular source IP address or to a specific resource, it prevents a single entity or a distributed group of attackers from overwhelming the target with excessive traffic. This helps maintain service availability by dropping requests that exceed the defined limits.
- ✓
Scrubbing centers
Why this is correct
Scrubbing centers are specialized, high-capacity data centers designed to analyze and filter out malicious traffic, particularly during large-scale Distributed Denial of Service (DDoS) attacks. When an attack is detected, incoming traffic is rerouted through these centers, where advanced filtering technologies identify and remove attack packets while allowing legitimate traffic to proceed to the intended destination. This offloads the attack burden from the target's infrastructure, ensuring business continuity and service availability.
- ✗
MAC filtering
Why it's wrong here
MAC filtering is a Layer 2 access control method that permits or denies network access based on a device's unique Media Access Control (MAC) address. While it can be used for basic access control on small, static networks, it is easily bypassed by MAC spoofing and is entirely ineffective against Distributed Denial of Service (DDoS) attacks. DDoS attacks typically involve a vast number of spoofed or legitimate, but compromised, IP addresses and operate at higher network layers, rendering MAC-based filtering irrelevant for large-scale volumetric attacks.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.