Courseiva

CEH Practice Question: Malware, Social Engineering and Network Attacks

Which TWO of the following are examples of application-layer DDoS attacks?

⚠ Common exam trap

It's easy for candidates to confuse network/transport-layer attacks (like SYN flood, ICMP flood, UDP flood) with application-layer attacks, failing to recognize that Slowloris and HTTP flood specifically exploit HTTP protocol behavior at Layer 7.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Slowloris

Slowloris (B) is an application-layer DDoS attack because it operates at Layer 7 by opening many partial HTTP connections and sending incomplete request headers, exhausting the web server's connection pool without ever completing a request. HTTP flood (D) is also an application-layer attack, since it overwhelms a web server with a high volume of seemingly legitimate HTTP GET or POST requests that consume CPU, memory, and application resources. In contrast, ICMP flood (A), SYN flood (C), and UDP flood (E) are network- or transport-layer attacks: ICMP and UDP floods simply blast packets at Layers 3/4, and a SYN flood exploits the TCP three-way handshake at Layer 4, so none of them target application-layer protocols like HTTP.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ICMP flood

    Why it's wrong here

    An ICMP flood is a network-layer (Layer 3) denial-of-service attack that overwhelms a target system or network with a massive volume of ICMP Echo Request packets. The target's resources are consumed as it attempts to process and respond to each incoming ping request, exhausting its bandwidth and CPU cycles. This attack directly targets the network's ability to handle basic connectivity, rather than specific application services.

  • ✓

    Slowloris

    Why this is correct

    Slowloris is an application-layer (Layer 7) denial-of-service attack specifically designed to exhaust a web server's connection pool. It achieves this by initiating numerous HTTP connections and then sending partial HTTP requests, such as incomplete headers, at very slow intervals. This forces the server to keep these connections open indefinitely, waiting for the full request, thereby preventing legitimate users from establishing new connections and accessing the web service.

  • ✗

    SYN flood

    Why it's wrong here

    A SYN flood is a transport-layer (Layer 4) denial-of-service attack that exploits the TCP three-way handshake mechanism. The attacker sends a large number of TCP SYN requests to the target server but never completes the handshake by sending the final ACK packet. This leaves the server with numerous half-open connections in its memory, quickly exhausting its connection table and preventing new, legitimate TCP connections from being established.

  • ✓

    HTTP flood

    Why this is correct

    An HTTP flood is an application-layer (Layer 7) denial-of-service attack that aims to overwhelm a web server by sending a high volume of seemingly legitimate HTTP GET or POST requests. Unlike lower-layer attacks, these requests complete the TCP handshake and appear normal, making them challenging to filter without impacting legitimate traffic. The attack exhausts server resources like CPU, memory, and database connections by forcing the server to process each request fully.

  • ✗

    UDP flood

    Why it's wrong here

    A UDP flood is a network-layer (Layer 3) denial-of-service attack that saturates the target's network bandwidth with a large volume of User Datagram Protocol (UDP) packets. These packets are often sent to random ports on the target server, which then expends resources attempting to identify the listening application. When no application is found, the server typically generates an ICMP Destination Unreachable packet, consuming both inbound and outbound bandwidth and server processing power.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

This CEH question is part of Courseiva's 913-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.