Courseiva
Network Security →mediumMultiple Select

ISC2 CC Network Security Practice Question

Which THREE of the following are common mitigation techniques against Denial of Service (DoS) attacks?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implementing rate limiting on servers

DoS mitigation includes using DDoS protection services, rate limiting, and filtering traffic based on IP reputation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implementing rate limiting on servers

    Why this is correct

    Rate limiting caps the number of requests a server accepts per client within a time window, throttling floods before they exhaust connection or processing capacity. This directly satisfies the DoS mitigation requirement by preserving availability for legitimate users during volumetric or application-layer attacks.

  • ✗

    Disabling all firewall rules

    Why it's wrong here

    Disabling firewall rules removes the filtering that absorbs or drops attack traffic, leaving every instance exposed. It is tempting because firewalls can themselves become bottlenecks, and it would be correct if the firewall were the single point of failure being bypassed during an attack.

  • ✗

    Allowing all inbound traffic to avoid blocking legitimate users

    Why it's wrong here

    Permitting all inbound traffic gives attackers unrestricted access, amplifying rather than mitigating a DoS attack. It is tempting because availability is the goal, and it would be correct in a scenario where over-restrictive filtering is blocking legitimate users and traffic must be widened deliberately.

  • ✓

    Filtering traffic based on IP reputation

    Why this is correct

    IP reputation filtering blocks or rate-limits traffic from addresses with known malicious or abusive history, using threat intelligence feeds. This drops attack traffic close to the source before it consumes server or bandwidth resources, mitigating volumetric and application-layer denial of service.

  • ✓

    Using a Content Delivery Network (CDN) to absorb traffic

    Why this is correct

    A CDN terminates and distributes incoming requests across globally dispersed edge nodes, absorbing volumetric traffic before it reaches origin servers. This satisfies the DoS mitigation requirement by preventing attack traffic from exhausting the origin's bandwidth or connection capacity.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.