easyMultiple Choice
CISM Practice Question: Experiences a DDoS attack that overwhelms their…
An organization experiences a DDoS attack that overwhelms their internet connection. Which containment strategy would be MOST effective?
⚠ Common exam trap
The trap is choosing on-premises controls (firewall rules, shutting down connectivity) for a volumetric attack that saturates the internet link, when only upstream/ISP-level mitigation can be effective.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Contact the ISP for traffic scrubbing or blackhole routing.
When a DDoS attack saturates the organization's internet connection, on-premises controls like firewalls cannot help because the pipe itself is full. The most effective containment is to engage the ISP (or a cloud scrubbing provider) to perform traffic scrubbing — filtering malicious traffic and forwarding clean traffic — or blackhole routing to drop the attack traffic upstream. This moves the mitigation to where there is sufficient capacity and routing control, preserving the organization's limited bandwidth.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Shut down all external connectivity.
Why it's wrong here
Shutting down all external connectivity severs the attack but also halts legitimate customer and business traffic, causing self-inflicted outage. It is tempting because it guarantees immediate relief, and it would suit a targeted intrusion where isolation is required, but a DDoS needs filtering that preserves genuine users.
- ✗
Change firewall rules to block all traffic.
Why it's wrong here
Blocking all traffic at the firewall discards legitimate sessions alongside malicious ones, so the service stays unavailable to real users. It is tempting because firewall rules are quick to apply, and blanket denial suits a compromised host, but a DDoS demands selective filtering or scrubbing that separates attack traffic from valid requests.
- ✗
Add more bandwidth to absorb the attack.
Why it's wrong here
Adding bandwidth cannot absorb a volumetric flood; the attacker simply scales traffic and the connection still saturates, so the service remains unavailable. It is tempting because capacity planning genuinely mitigates traffic spikes, but that works for legitimate demand growth, not for an adversary deliberately exceeding link capacity.
- ✓
Contact the ISP for traffic scrubbing or blackhole routing.
Why this is correct
Volumetric flooding saturates the internet link before traffic reaches perimeter defences, so on-premises controls cannot help. Upstream scrubbing centres filter malicious flows, or blackhole routing drops targeted prefixes at the ISP, absorbing the attack closer to its source and restoring legitimate connectivity.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.