ISC2 CC Network Security Practice Question
Which THREE of the following are common mitigation techniques against Denial of Service (DoS) attacks?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implementing rate limiting on servers
DoS mitigation includes using DDoS protection services, rate limiting, and filtering traffic based on IP reputation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implementing rate limiting on servers
Why this is correct
Rate limiting caps the number of requests a server accepts per client within a time window, throttling floods before they exhaust connection or processing capacity. This directly satisfies the DoS mitigation requirement by preserving availability for legitimate users during volumetric or application-layer attacks.
- ✗
Disabling all firewall rules
Why it's wrong here
Disabling firewall rules removes the filtering that absorbs or drops attack traffic, leaving every instance exposed. It is tempting because firewalls can themselves become bottlenecks, and it would be correct if the firewall were the single point of failure being bypassed during an attack.
- ✗
Allowing all inbound traffic to avoid blocking legitimate users
Why it's wrong here
Permitting all inbound traffic gives attackers unrestricted access, amplifying rather than mitigating a DoS attack. It is tempting because availability is the goal, and it would be correct in a scenario where over-restrictive filtering is blocking legitimate users and traffic must be widened deliberately.
- ✓
Filtering traffic based on IP reputation
Why this is correct
IP reputation filtering blocks or rate-limits traffic from addresses with known malicious or abusive history, using threat intelligence feeds. This drops attack traffic close to the source before it consumes server or bandwidth resources, mitigating volumetric and application-layer denial of service.
- ✓
Using a Content Delivery Network (CDN) to absorb traffic
Why this is correct
A CDN terminates and distributes incoming requests across globally dispersed edge nodes, absorbing volumetric traffic before it reaches origin servers. This satisfies the DoS mitigation requirement by preventing attack traffic from exhausting the origin's bandwidth or connection capacity.
Go deeper
Related to this question
Key term
Denial-of-service
A Denial-of-service (DoS) attack is an attempt to make a computer, network, or online service unavailable to its intended users by overwhelming it with fake traffic or requests.
Key term
DDoS
A DDoS (Distributed Denial-of-Service) attack is a malicious attempt to disrupt normal traffic of a targeted server, service, or network by overwhelming it with a flood of internet traffic from multiple compromised systems.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.