312-50 exam dumps

312-50 practice question 239 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 239

Single answer▪ DoS/DDoS Attack Countermeasures

A company hosts a public customer portal behind a single internet-facing web server. During a promotional event, the portal becomes unavailable as inbound traffic spikes to many times the normal level. Monitoring shows the server CPU is not saturated, but the internet link is fully consumed by a flood of unsolicited TCP and UDP traffic from thousands of distributed source IP addresses. Management wants the fastest effective countermeasure that preserves service availability during the attack. Which action is the BEST response?

  1. A

    Enable host-based antivirus and perform a full malware scan on the web server

  2. B

    Ask the ISP or a DDoS mitigation provider to apply upstream traffic scrubbing and filtering before the traffic reaches the company link

  3. C

    Increase the web server CPU and RAM allocation to handle the extra traffic locally

  4. D

    Disable TLS on the portal to reduce cryptographic overhead during the event

Show answer and explanation

Correct answer: B

Explanation

This scenario describes a volumetric DDoS attack: the key indicators are a fully consumed internet link, unsolicited TCP/UDP traffic, and many distributed source IP addresses. In such cases, local countermeasures on the web server are insufficient because the bottleneck is upstream bandwidth. Best practice is to engage the ISP or a cloud-based DDoS mitigation provider to scrub, filter, or reroute malicious traffic before it reaches the victim network. This aligns with standard DDoS defense guidance from major providers and industry best practices: mitigate as far upstream as possible, use traffic scrubbing centers or CDN/Anycast-based protection for public services, and coordinate with the ISP for rapid response. Local hardening, server scaling, and application tuning are useful secondary controls, but they do not restore availability when the circuit itself is overwhelmed.

  • A. Incorrect.

    Incorrect. A host-based antivirus scan does not address a bandwidth-exhaustion DDoS condition. The scenario specifically states that the server CPU is not saturated and that the internet link is the bottleneck. Malware scanning may be relevant for host compromise investigations, but it is not an effective immediate countermeasure for a volumetric distributed flood.

  • B. Correct.

    Correct. When a DDoS attack saturates the victim's upstream internet link, the most effective immediate countermeasure is upstream mitigation such as ISP blackholing, rate-limiting, ACLs, or preferably DDoS scrubbing/cleaning services. This works because malicious traffic is filtered before it reaches and overwhelms the organization's circuit. In a distributed attack using many source IPs, blocking traffic locally at the server or firewall is often too late because the link is already congested.

  • C. Incorrect.

    Incorrect. Adding CPU and RAM helps with resource exhaustion on the host, such as application-layer overload, but it does not solve a saturated WAN link. In this scenario, the server itself is not the limiting factor. Candidates may choose this because scaling is a valid resilience strategy for some availability issues, but it is not the best response to a volumetric DDoS consuming the network circuit.

  • D. Incorrect.

    Incorrect. Disabling TLS may reduce some server-side processing overhead, but the problem described is link saturation from unsolicited traffic, not cryptographic exhaustion. It could also weaken security and may have little or no impact on the flood volume. This reflects a common misconception that any performance optimization helps equally against all forms of DoS.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam