CEH Practice Question: Malware, Social Engineering and Network Attacks
Which TWO of the following are examples of application-layer DDoS attacks? (Select 2)
⚠ Common exam trap
A common pitfall for EC-CEH candidates is misclassifying network-layer floods (UDP, ICMP, SYN) as application-layer attacks. Application-layer attacks target Layer 7 protocols like HTTP; HTTP flood and Slowloris are examples that exhaust web server resources rather than network bandwidth.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
HTTP flood
HTTP flood (B) is correct because it operates at the application layer (Layer 7), overwhelming a web server with seemingly legitimate HTTP GET or POST requests that consume server resources and bandwidth. Slowloris (C) is also correct because it is a Layer 7 attack that opens many partial HTTP connections and sends incomplete headers, keeping sockets open and exhausting the web server's connection pool without needing high bandwidth. UDP flood (A) is incorrect because it is a volumetric transport-layer (Layer 4) attack that sends large numbers of UDP packets to random ports. ICMP flood (D) is incorrect because it is a network-layer (Layer 3) attack using ICMP echo requests. SYN flood (E) is incorrect because it exploits the TCP handshake at the transport layer (Layer 4) by sending many SYN packets without completing the connection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
UDP flood
Why it's wrong here
A UDP flood saturates bandwidth and processing with connectionless datagrams at the transport layer, never invoking application logic. It is tempting because it denies service, but the mechanism is layer 4. Application-layer attacks instead exhaust resources through HTTP, DNS or similar protocol requests.
- ✓
HTTP flood
Why this is correct
An HTTP flood exhausts server resources by sending massive volumes of seemingly legitimate GET or POST requests, operating at layer 7. It matches the stem's application-layer criterion, unlike volumetric network-layer attacks such as UDP or SYN floods.
- ✓
Slowloris
Why this is correct
Slowloris exhausts a web server's connection table by opening many partial HTTP requests and holding them open, sending headers slowly to prevent timeouts. Operating at the application layer, it satisfies the stem's requirement by targeting HTTP rather than network or transport resources, and needs far fewer packets than volumetric floods.
- ✗
ICMP flood
Why it's wrong here
An ICMP flood consumes bandwidth and processing with echo requests at the network layer, so it cannot be an application-layer attack. It is tempting because it overwhelms a target, but the mechanism is layer 3. Application-layer attacks abuse HTTP, DNS or other protocol requests instead.
- ✗
SYN flood
Why it's wrong here
A SYN flood exhausts TCP connection state at the transport layer by leaving handshakes half-open; it never reaches application protocols. It is tempting because it targets web servers, but the mechanism is layer 4. Application-layer attacks instead exhaust resources via HTTP, DNS or similar protocol requests.
Visual reference
Go deeper
Related to this question
About these practice questions
This CEH question is part of Courseiva's 913-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.