Skip to content
ScopefileGet the app

Module 10Domain 4 of 9Network and Perimeter Hacking

Denial-of-service and DDoS attacks

A denial-of-service attack makes a system unavailable to the people allowed to use it by exhausting something it depends on: link bandwidth, connection state, or the server's capacity to answer. A distributed attack (DDoS) does the same from many sources at once. Sort each attack by the resource it drains and the matching defense layer follows.

Exam
312-50
Domain
4 of 9
Domain weight
24%
This file
~5%
Targets
16

Four classes, four different things running out

DoS classes by the resource they exhaust, the clue an analyst sees, and the defenses that match
ClassWhat runs outWhat the analyst seesDefenses that fit
Volumetric, including reflection and amplificationBandwidth on the link or further upstreamInbound traffic pinned at the circuit's ceiling; replies arriving that no internal host requested, from many servers of one UDP serviceUpstream scrubbing or ISP filtering, anycast and CDN capacity, ingress filtering of spoofed source addresses at the networks traffic leaves
Protocol (state exhaustion)Connection tables on servers, firewalls and load balancersHalf-open connections piling up, a firewall state table at its limit, device CPU high while the link still has room; malformed or fragmented packets in capturesHandshake proxying at the edge, state tables sized with short timeouts, dropping malformed packets
Application layerWorker threads, database time, application logicNetwork graphs normal while response times climb; logs show heavy traffic to one expensive URL, or many connections that send headers slowly and never finishFiltering in front of the application, header and idle timeouts, caching in front of costly pages
Permanent DoS (PDoS)The device itselfThe system stays broken after the traffic stops and needs repair or replacementAuthenticated update channels, restricted management access, tested recovery images

MITRE ATT&CK files the first class under Network Denial of Service (T1498) and the application and service floods under Endpoint Denial of Service (T1499).

Where each defense sits, from source to server

Upstream defenses absorb size; defenses near the app read intent
Five-step chain from the networks traffic originates in to the application. Source networks filter spoofed addresses, the ISP or upstream scrubs volume, the network edge proxies handshakes and limits state, the server host runs patches and timeouts, and the application uses WAF rules and per-client limits. The network edge is highlighted.01Sourcenetworksdrop spoofedsources02ISP upstreamscrubbing,filtering03Network edgehandshake proxy,state limits04Server hostpatches, timeouts05ApplicationWAF, per-clientlimitsFive-step chain from the networks traffic originates in to the application. Source networks filter spoofed addresses, the ISP or upstream scrubs volume, the network edge proxies handshakes and limits state, the server host runs patches and timeouts, and the application uses WAF rules and per-client limits. The network edge is highlighted.01Source networksdrop spoofed sources02ISP upstreamscrubbing, filtering03Network edgehandshake proxy, state limits04Server hostpatches, timeouts05ApplicationWAF, per-client limits

Reading the scenario, and the traps around it

Terms Module 10 covers

  • Botnet: a fleet of compromised machines answering to a command-and-control (C2) server. IoT devices left on default passwords are the usual recruits, which ties this module to IoT and OT hacking.
  • Reflection: requests carry the victim's forged address, so third-party servers send their replies to the victim. The weakness is networks that allow spoofed source addresses to leave.
  • Amplification: the reply is much larger than the request, so a small input becomes a big flood. ATT&CK T1498.002 covers reflection and amplification together.
  • Smurf: ICMP traffic aimed at a network's broadcast address with the victim as the forged source, so every host answers the victim. It relies on routers that forward directed broadcasts, and disabling that closes it.
  • Fraggle: the same broadcast trick using UDP instead of ICMP.
  • Ping of death: an oversized ICMP packet that crashed old network stacks on reassembly. Today it is vocabulary, closed by patching.
  • Slow-rate attack: connections opened and fed a trickle of data so the server's connection pool fills with clients that never finish. Low bandwidth, high damage.
  • Multi-vector attack: two or more classes combined in one campaign.

Clues that decide the class

Start from the defender's graphs. A full uplink points to volumetric. A firewall or load balancer choking on state while the link has headroom points to protocol. Healthy network graphs with a slow, erroring application point to the application layer. Damage that outlasts the traffic points to PDoS.

Look-alike traps

  • DoS vs DDoS: the class of attack can be identical; only the number of sources differs.
  • Botnet vs DDoS: the botnet is the infrastructure. It also sends spam and steals credentials, so a botnet in a scenario does not automatically mean a flood.
  • Reflection vs amplification: reflection is about where the replies go, amplification is about how big they get. Real attacks usually do both.
  • Smurf vs Fraggle: ICMP vs UDP, same broadcast weakness.
  • Flash crowd vs DDoS: a legitimate surge after a news mention can fill the same bandwidth graph as a flood. The difference is who is sending and why, which a traffic graph alone cannot show.
  • Slow-rate vs flood: a slow-rate attack barely moves the traffic graph, so bandwidth alarms miss it and connection-level timeouts catch it.

Where the attack bends TCP state to take over a session instead of exhausting it, you are in Module 11, session hijacking. Detection placement (IDS watching, IPS dropping inline) is laid out on IDS vs IPS vs firewall.

Authorization before any availability test

Availability testing is the riskiest thing a tester can do to a client, so it needs explicit written authorization naming the targets, the time window and the stop conditions. Traffic crosses ISPs and cloud platforms that never signed the contract, so their terms may require separate approval. Plenty of engagements exclude DoS from scope entirely. That is the same line the ethical hacking vs penetration testing file draws: permission and scope define the work.

What to skip

Named-botnet histories, record attack sizes from the news, and the brand names of commercial protection products. None of them help you classify an attack or pick a defense.

Name the drained resource

Each target describes an outage from the defender's seat. The note under each option explains why that defense fits the class or misses it.

Answered 0/16Hits 0

T-01

An ISP notifies an organization that its internal Memcached servers are actively participating in a massive DDoS attack against a third party. Which operational fix should the organization prioritize to stop this weaponization?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ABlocking all outbound UDP would break legitimate services such as DNS and VoIP, a disproportionate fix for one misconfigured service.
  2. BMemcached amplification abuses spoofed UDP requests, so filtering inbound TCP SYN packets does not address it.
  3. CA CDN and WAF protect your own services from inbound attacks, but your servers are the attackers' reflectors, sending traffic to a third party.
  4. DCorrect: disabling Memcached's UDP interface and restricting access to trusted clients stops attackers from using the servers as amplifiers.
T-02

During an incident, network telemetry reveals a massive spike in packets-per-second (pps) with relatively low bits-per-second (bps), alongside extremely high source IP entropy. Which attack vector does this flow-level divergence MOST likely indicate?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ASlow-rate attacks use few packets and hold connections open, which is the opposite of a massive packet-per-second spike.
  2. BLarge-payload saturation would drive bits per second up, not produce high packet rates with low bandwidth.
  3. CHTTP POST floods require completed TCP connections, so they cannot use randomized spoofed sources at very high packet rates.
  4. DCorrect: many tiny packets from randomized, spoofed source addresses produce high packet rates with modest bandwidth, typical of a SYN or similar flood.
T-03

During an anticipated flash sale, an e-commerce platform experiences severe database latency and checkout failures. Logs reveal thousands of valid-looking POST requests containing unique cookies. Which mitigation strategy best addresses this without severely disrupting actual buyers?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ABlackholing drops all traffic to the endpoint, taking checkout offline for real buyers and achieving the attacker's goal.
  2. BGlobal CAPTCHAs on every checkout add heavy friction for legitimate buyers during a sale, hurting conversions.
  3. CCorrect: behavior-based WAF rules can spot automated request patterns and challenge or block them while letting real buyers through.
  4. DSYN backlog tuning helps with TCP handshake floods, but these are complete, valid-looking HTTP requests at the application layer.
T-04

An attacker injects malicious firmware updates into a robot used in a manufacturing plant, causing it to malfunction permanently. What type of attack is this?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: phlashing, or permanent denial of service, corrupts device firmware so the hardware is unusable until reflashed or replaced; signed firmware updates help prevent it.
  2. BFragmentation attacks abuse IP packet reassembly to evade filters or crash stacks, not malicious firmware updates.
  3. CJamming disrupts wireless signals with interference rather than altering device firmware.
  4. DOverheating is not a recognized attack category here, and the scenario specifically involves malicious firmware.
T-05

Using a botnet to overwhelm a network with malicious traffic is known as:

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AA teardrop attack sends overlapping IP fragments that crash vulnerable stacks, and does not require a botnet.
  2. BPing of Death sends oversized ICMP packets to crash a host, a single-source attack patched long ago.
  3. CCorrect: a DDoS uses many compromised machines, a botnet, to flood a target from numerous sources at once.
  4. DA Smurf attack spoofs ICMP echo requests to broadcast addresses so many hosts reply to a victim, an amplification technique rather than a botnet.
T-06

What type of attack overwhelms a network or service by flooding it with excessive traffic, rendering it unusable?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: a denial-of-service attack exhausts bandwidth or system resources so legitimate users cannot reach the service.
  2. BPhishing deceives people into revealing information and does not flood services with traffic.
  3. CA man-in-the-middle attack intercepts or alters communications instead of making services unavailable.
  4. DBrute force guesses credentials repeatedly; the aim is access, not rendering the service unusable.
T-07

A mission-critical endpoint is targeted by a severe volumetric DDoS attack. The operations team must decide between invoking immediate BGP blackholing or routing the traffic to a cloud scrubbing center. Which operational trade-off is accurate?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: blackholing drops everything destined for the target, legitimate users included, so it protects the wider network while completing the outage the attacker wanted.
  2. BBlackholing cannot distinguish legitimate from malicious traffic; it discards all traffic to the destination.
  3. CScrubbing centers are built specifically to filter volumetric Layer 3 and Layer 4 attacks.
  4. DRerouting through a scrubbing center adds some latency, so guaranteed zero latency is false.
T-08

Which attack sends malformed fragmented IP packets with overlapping offset values that can crash systems when reassembled?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AA land attack sends packets whose source and destination address and port are identical to the target's own, rather than overlapping fragments.
  2. BA Fraggle attack floods a network with spoofed UDP broadcast traffic for amplification, which differs from crashing a host through malformed fragments.
  3. CSlowloris is an application-layer attack that holds many HTTP connections open with partial requests, not a fragment reassembly flaw.
  4. DCorrect: Teardrop sends IP fragments with overlapping offsets that crash vulnerable reassembly code; patched modern TCP/IP stacks and fragment-filtering devices neutralize it.
T-09

A multi-stage attack begins with DNS amplification, shifts to TCP SYN flooding, and introduces slow HTTP POST requests. Which response sequence provides the MOST comprehensive layered defense across all three phases?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AUniform rate limiting cannot address protocol-specific behavior; slow HTTP attacks stay under generic limits.
  2. BRelying solely on a CDN while removing local defenses leaves gaps, especially for traffic that reaches the origin directly.
  3. CCorrect: DNS hardening and upstream ISP filtering absorb amplification, SYN cookies counter the SYN flood, and WAF behavioral rules catch slow HTTP POSTs.
  4. DSYN cookies address only the SYN flood phase; they do nothing against DNS amplification volume or slow HTTP requests.
T-10

You are overseeing the security of your network to mitigate the risk of DoS attacks. Which of the following is NOT a recommended practice?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: delaying security updates leaves known vulnerabilities, including ones that crash services, open for longer, the opposite of good practice.
  2. BRate limiting caps how many requests a client can make, blunting floods and abusive traffic.
  3. CAn IDS helps detect attack patterns early, so teams can respond to DoS attempts.
  4. DStrong authentication limits who can reach resource-intensive functions and helps prevent abuse of accounts used in attacks.
T-11

A hacker is attempting to overwhelm a company's online service by sending an exceptionally large number of simultaneous requests. What mitigation strategy can effectively reduce the risk of this type of Denial-of-Service (DoS) attack?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ASYN cookies protect against TCP SYN floods at the handshake level, not against floods of complete application requests.
  2. BA WAF can help filter malicious web requests, but limiting each client's request rate is the most direct control here.
  3. CDisabling ICMP stops ping-based attacks only and does nothing against high volumes of service requests.
  4. DCorrect: rate limiting caps the requests each client can send within a time window, so no single source can overwhelm the service.
T-12

During a penetration test, you are requested to evaluate a website's ability to withstand a denial of service attack. Which of the following tools would you MOST LIKELY use for this purpose?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ANetcat is a general-purpose utility for reading and writing raw TCP or UDP connections, handy for banner checks and debugging rather than for generating sustained load.
  2. BHyena is a Windows administration tool for managing and enumerating Active Directory users, groups and shares, so it has nothing to do with resilience testing.
  3. CNikto is a web server scanner that reports outdated software, risky files and misconfigurations; it looks for weaknesses instead of measuring how a site copes with floods.
  4. DCorrect: Low Orbit Ion Cannon is a well-known traffic-flooding tool, so it is the one that simulates DoS load in an authorized test; its unmasked source addresses make it easy to block.
T-13

An online gaming server is experiencing a persistent SYN flood attack, causing legitimate players to be unable to connect. Which of the following mitigation techniques would help alleviate this type of attack?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AA larger connection buffer only delays exhaustion, because a flood of half-open handshakes simply fills the bigger queue as well.
  2. BCorrect: SYN cookies let the server avoid allocating connection state until the client completes the three-way handshake, so spoofed half-open requests no longer exhaust the backlog queue.
  3. CA SYN flood uses TCP, so blocking UDP does nothing against it and would also break legitimate game traffic that commonly runs over UDP.
  4. DBlocking every non-local subnet would lock out the remote players the server exists for, turning the defense itself into a denial of service.
T-14

Why might an attacker utilize a Distributed Denial of Service (DDoS) attack on an e-commerce website?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: A DDoS attack takes the storefront offline, so its typical goal is disruption, lost sales and reputational harm, whether driven by rivals, extortion or grudges.
  2. BFlooding a site with traffic slows or stops checkout for everyone; no attacker motive involves making legitimate purchases faster.
  3. CA DDoS consumes bandwidth or server resources but grants no privileges; gaining administrative rights requires an exploit or stolen credentials.
  4. DExfiltration needs access to the data store, which a DDoS does not provide, although a flood is sometimes used as a smokescreen for a separate intrusion.
T-15

What type of attack occurs when an attacker floods a network device with ICMP Echo Requests (ping) to make it unresponsive?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AAn evil twin is a rogue wireless access point that imitates a legitimate SSID to lure clients, not a flood of ping packets against a device.
  2. BA rogue AP is any unauthorized access point attached to the network; it is a wireless policy problem, not a traffic-exhaustion attack.
  3. CCorrect: Overwhelming a device with ICMP Echo Requests until it cannot answer real traffic is an ICMP (ping) flood, a classic denial-of-service attack mitigated by rate-limiting ICMP.
  4. DA replay attack resends captured valid traffic, such as authentication messages, to reproduce its effect; it aims at access, not at exhausting resources.
T-16

An attacker has gained unauthorized access to a cloud service provider and launched an amplification attack using DNS servers, overwhelming the target's network with traffic. Which of the following would be an appropriate mitigation method for this attack?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ALowering the TTL only changes how long resolvers cache records; it does nothing to limit the oversized responses that open resolvers reflect toward a victim.
  2. BTLS protects confidentiality and integrity of data in transit but does not reduce reflected DNS volume.
  3. CCorrect: Response rate limiting and filtering, together with closing open recursion, cap how much amplified traffic a DNS server can reflect at a spoofed victim address.
  4. DExtra firewalls at the victim's edge cannot help once the inbound link is already saturated; amplification is mitigated at the reflectors and upstream scrubbing.

What else to settle about Module 10

What does the CEH blueprint list under Module 10?

DoS and DDoS concepts, botnets, attack techniques, a case study, countermeasures and protection tools. Module 10 sits in Domain 4, Network and Perimeter Hacking, weighted at 24% across five modules (EC-Council CEH Exam Blueprint v5.0, as of Oct 11, 2026). The concepts and countermeasures carry this page; the case study does not.

How is a DoS outage different from a ransomware outage?

Both hit availability. Ransomware encrypts data and the system stays down until it is restored or decrypted. A flooding attack exhausts a resource, and service usually returns once the traffic stops or is filtered. PDoS is the exception that leaves lasting damage.

Is a DoS test part of a normal penetration test?

Only when the client writes it into scope. Expect it to be excluded by default, and when it is included, expect fixed windows, named targets, agreed stop conditions and sign-off from the hosting or cloud provider.

Sources