N10-009 exam dumps

N10-009 practice question 264 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 264

Single answerDenial-of-service (DoS)/distributed denial-of-service (DDoS)

A company hosts a public e-commerce website in its on-premises data center. During a flash sale, users begin reporting that the site is unreachable. The network administrator sees the internet circuit is saturated and the firewall shows hundreds of thousands of inbound HTTPS connection attempts per minute from many different public IP addresses across multiple countries. Internal servers are healthy, and no single source IP is generating enough traffic to be blocked individually. Which action would BEST mitigate this attack while keeping the website available to legitimate users?

  1. A

    Enable account lockout policies on the web application to stop the malicious traffic

  2. B

    Ask the ISP or a DDoS mitigation provider to implement upstream traffic scrubbing/filtering for the public site

  3. C

    Block all inbound traffic from foreign countries at the local firewall and reboot the web servers

  4. D

    Disable HTTPS temporarily and require users to connect over HTTP so the firewall can inspect the traffic more easily

Show answer and explanation

Correct answer: B

Explanation

This scenario describes a distributed denial-of-service attack, specifically one in which many different source IP addresses generate large volumes of inbound traffic and connection attempts, overwhelming the organization's internet connection. Because the attack saturates the upstream circuit, the best mitigation is to involve the ISP or a cloud-based DDoS protection provider that can scrub or absorb malicious traffic before it reaches the customer's edge. This aligns with common industry best practices from major providers and guidance such as CISA and NIST recommendations on DDoS response: mitigate as far upstream as possible, use ISP/provider coordination, and preserve service availability for legitimate users. Local actions such as rebooting servers, changing authentication settings, or relying only on firewall blocks are often insufficient once the WAN link is already congested.

  • A. Incorrect.

    This is incorrect. Account lockout policies help address authentication abuse such as password guessing or credential stuffing against user accounts, but they do not mitigate a volumetric or distributed denial-of-service attack saturating the internet circuit. In this scenario, the issue is excessive inbound connection attempts from many distributed sources, not repeated login failures against specific accounts.

  • B. Correct.

    This is correct. When a DDoS attack saturates the organization's internet connection, mitigation must occur upstream before the traffic reaches the local circuit. ISP-based blackholing/scrubbing or a dedicated DDoS mitigation service can filter, rate-limit, or absorb malicious traffic while forwarding legitimate traffic to the website. This is the most effective choice for preserving availability during a large distributed attack.

  • C. Incorrect.

    This is incorrect. Geoblocking may reduce some unwanted traffic in limited cases, but it is not a reliable primary response when the attack is distributed and the business likely serves legitimate users broadly. More importantly, if the circuit is already saturated, local firewall rules may not help because the bottleneck exists before traffic reaches internal resources. Rebooting healthy web servers does not address a bandwidth-exhaustion attack.

  • D. Incorrect.

    This is incorrect. Disabling HTTPS would weaken security and would not solve the core issue of a DDoS attack consuming bandwidth and connection capacity. HTTP would expose user sessions and payment-related interactions to risk, which is unacceptable for an e-commerce site. Also, many modern firewalls can inspect HTTPS with proper configuration, but inspection is not the primary fix when the link itself is overwhelmed.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam