CEH Practice Question: Malware, Social Engineering and Network Attacks
Which TWO of the following are examples of application layer DDoS attacks? (Select two.)
⚠ Common exam trap
The CEH exam often tests the distinction between Layer 4 (transport) and Layer 7 (application) attacks, and the trap here is that candidates may confuse SYN flood (a TCP-based Layer 4 attack) with an application layer attack because it targets web servers, but it operates at a lower layer of the OSI model.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Slowloris
Slowloris (A) is an application-layer (Layer 7) DDoS attack because it opens many partial HTTP connections and sends incomplete request headers, exhausting the web server's connection pool without ever completing a request. HTTP flood (D) is also an application-layer attack, since it overwhelms a web server with seemingly legitimate HTTP GET or POST requests that consume CPU, memory, and application resources. By contrast, UDP flood (B) is a volumetric transport/network-layer attack that saturates bandwidth with User Datagram Protocol packets. Smurf attack (C) is an ICMP-based network-layer amplification attack using broadcast addresses and spoofed source IPs. SYN flood (E) is a transport-layer attack that exploits the TCP three-way handshake by leaving half-open connections, not an application-layer attack.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Slowloris
Why this is correct
Slowloris holds many partial HTTP requests open by sending headers slowly, exhausting the web server's connection pool. It targets the application layer by abusing legitimate HTTP behaviour rather than flooding the network stack with volume.
- ✗
UDP flood
Why it's wrong here
A UDP flood saturates bandwidth and processing at the transport layer with connectionless datagrams; it does not exercise application logic. It is tempting because UDP is used by DNS and streaming services, but UDP floods are volumetric layer 3/4 attacks, not application-layer ones.
- ✗
Smurf attack
Why it's wrong here
A Smurf attack floods a victim via ICMP echo requests sent to a network's broadcast address, operating at the network layer, not the application layer. It tempts because it is a classic volumetric DDoS technique, but application layer attacks target services such as HTTP or DNS with valid-looking requests.
- ✓
HTTP flood
Why this is correct
An HTTP flood overwhelms a web server with numerous seemingly valid GET or POST requests, consuming application and database resources. It operates at layer 7, distinguishing it from volumetric network-layer attacks such as UDP or ICMP floods.
- ✗
SYN flood
Why it's wrong here
A SYN flood exhausts the TCP connection table at layer 4 by sending half-open handshakes; it never reaches the application. It is tempting because it targets web-facing services, but SYN floods are transport-layer attacks. Application-layer attacks target HTTP, DNS or similar protocols.
Visual reference
Go deeper
Related to this question
About these practice questions
This CEH question is part of Courseiva's 913-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.