Courseiva
Network Security →hardMultiple Select

ISC2 CC Network Security Practice Question

A company is experiencing a distributed denial-of-service (DDoS) attack that is overwhelming the network bandwidth. Which THREE mitigation techniques are most effective?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable rate limiting on network devices

Traffic filtering, rate limiting, and using a CDN can help absorb DDoS traffic. Changing IP addresses is reactive and not a standard mitigation; disabling ICMP may help against some attacks but is not a primary mitigation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable rate limiting on network devices

    Why this is correct

    Rate limiting caps the packet or connection rate accepted per source or interface, preventing a flood from consuming all available bandwidth. This directly satisfies the stem's bandwidth-overwhelm constraint by throttling excessive traffic at network devices.

  • ✗

    Disable ICMP on all devices

    Why it's wrong here

    Disabling ICMP removes only ping and traceroute replies, leaving the bandwidth-saturating flood itself untouched. It is tempting as a hardening step against ICMP-based reconnaissance or smurf amplification, but volumetric attacks need upstream scrubbing, rate limiting or traffic diversion instead.

  • ✗

    Change the public IP address of the server

    Why it's wrong here

    Changing the public IP address does not stop a flood already saturating the access circuit, and DNS propagation leaves the old address reachable. It is tempting as an evasion tactic against a single targeted IP, but volumetric DDoS requires upstream scrubbing or blackhole routing at the provider.

  • ✓

    Use a content delivery network (CDN) to absorb traffic

    Why this is correct

    A CDN terminates and distributes traffic across many edge locations, absorbing volumetric floods so the origin network's bandwidth is not overwhelmed. This directly satisfies the stem's bandwidth-exhaustion constraint by spreading load away from the target.

  • ✓

    Implement traffic filtering at the perimeter

    Why this is correct

    Perimeter traffic filtering drops malicious packets at the network edge before they consume internal bandwidth, directly relieving the bandwidth exhaustion described in the stem. Filtering by source, protocol or signature reduces the flood volume reaching protected hosts.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.