Courseiva

CEH Practice Question: Malware, Social Engineering and Network Attacks

Which TWO of the following are examples of protocol-based DoS attacks? (Choose two.)

⚠ Common exam trap

The CEH exam often tests the distinction between protocol-based attacks (exploiting protocol behavior like ICMP or TCP handshake) and application-layer attacks (like HTTP flood or Slowloris) or volumetric floods (like UDP flood), leading candidates to mistakenly include HTTP flood or UDP flood as protocol-based.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Smurf attack

A Smurf attack (A) is a protocol-based DoS attack because it abuses ICMP by sending echo requests to a network's broadcast address with a spoofed source IP, causing every host to reply to the victim and amplifying traffic. A SYN flood (B) is protocol-based because it exploits the TCP three-way handshake: the attacker sends many SYN packets with spoofed source addresses, filling the victim's half-open connection table so legitimate connections cannot complete. HTTP flood (C) and Slowloris (D) are application-layer (Layer 7) attacks that target web services rather than exploiting a network protocol's mechanics, and UDP flood (E) is a volumetric attack that simply overwhelms bandwidth with generic UDP datagrams rather than abusing a specific protocol behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Smurf attack

    Why this is correct

    The Smurf attack is a classic example of a protocol-based DoS because it leverages the Internet Control Message Protocol (ICMP). Attackers send ICMP echo requests (ping requests) to a network's broadcast address, spoofing the source IP address to be that of the victim. All hosts on the network then reply to the victim, overwhelming it with a flood of ICMP echo replies, effectively exploiting the ICMP protocol's functionality and network broadcast capabilities.

  • ✓

    SYN flood

    Why this is correct

    A SYN flood is a quintessential protocol-based DoS attack that specifically targets the Transmission Control Protocol (TCP) three-way handshake. The attacker sends a large volume of TCP SYN requests to the target server but never completes the handshake by sending the final ACK. This leaves the server with numerous half-open connections, exhausting its connection table resources and preventing legitimate users from establishing new connections.

  • ✗

    HTTP flood

    Why it's wrong here

    An HTTP flood is primarily an application-layer DoS attack, not a protocol-based one in the context of exploiting lower-level protocol mechanisms. This attack involves sending a massive number of legitimate or near-legitimate HTTP GET or POST requests to a web server. The goal is to consume the server's application resources, such as CPU, memory, and database connections, rather than exploiting vulnerabilities in the TCP/IP stack itself.

  • ✗

    Slowloris

    Why it's wrong here

    Slowloris is an application-layer DoS attack that operates by holding open as many HTTP connections to the target web server as possible for as long as it can. It achieves this by sending partial HTTP requests and then periodically sending additional HTTP headers, never completing the request. This ties up the server's connection resources, preventing new legitimate connections and differing from lower-level protocol exploitation.

  • ✗

    UDP flood

    Why it's wrong here

    While UDP is a protocol, a UDP flood is generally categorized as a volumetric DoS attack rather than a protocol-based one in the sense of exploiting specific protocol state machines or design flaws. The attack involves sending a large volume of UDP packets to random ports on the target server. The server expends resources generating ICMP "Destination Unreachable" replies, but the primary impact is bandwidth saturation, not a specific protocol mechanism exploitation beyond simple traffic generation.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.