ISC2 CC Network Security Practice Question
A company is experiencing a distributed denial-of-service (DDoS) attack that is overwhelming the network bandwidth. Which THREE mitigation techniques are most effective?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable rate limiting on network devices
Traffic filtering, rate limiting, and using a CDN can help absorb DDoS traffic. Changing IP addresses is reactive and not a standard mitigation; disabling ICMP may help against some attacks but is not a primary mitigation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable rate limiting on network devices
Why this is correct
Rate limiting caps the packet or connection rate accepted per source or interface, preventing a flood from consuming all available bandwidth. This directly satisfies the stem's bandwidth-overwhelm constraint by throttling excessive traffic at network devices.
- ✗
Disable ICMP on all devices
Why it's wrong here
Disabling ICMP removes only ping and traceroute replies, leaving the bandwidth-saturating flood itself untouched. It is tempting as a hardening step against ICMP-based reconnaissance or smurf amplification, but volumetric attacks need upstream scrubbing, rate limiting or traffic diversion instead.
- ✗
Change the public IP address of the server
Why it's wrong here
Changing the public IP address does not stop a flood already saturating the access circuit, and DNS propagation leaves the old address reachable. It is tempting as an evasion tactic against a single targeted IP, but volumetric DDoS requires upstream scrubbing or blackhole routing at the provider.
- ✓
Use a content delivery network (CDN) to absorb traffic
Why this is correct
A CDN terminates and distributes traffic across many edge locations, absorbing volumetric floods so the origin network's bandwidth is not overwhelmed. This directly satisfies the stem's bandwidth-exhaustion constraint by spreading load away from the target.
- ✓
Implement traffic filtering at the perimeter
Why this is correct
Perimeter traffic filtering drops malicious packets at the network edge before they consume internal bandwidth, directly relieving the bandwidth exhaustion described in the stem. Filtering by source, protocol or signature reduces the flood volume reaching protected hosts.
Visual reference
Go deeper
Related to this question
Learn chapter
Network Security Components and Controls
Key term
ICMP
ICMP is a network-layer protocol used by network devices to send error messages and operational information about network connectivity.
Key term
DDoS
A DDoS (Distributed Denial-of-Service) attack is a malicious attempt to disrupt normal traffic of a targeted server, service, or network by overwhelming it with a flood of internet traffic from multiple compromised systems.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.