ALL PASS, NO FAIL!

CEH v13 Module 10: Denial-of-Service Attacks — Free Practice Questions with Explanations

Last updated September 2026 · 10 questions · Module 10 of 20

Volume, protocol, and application-layer attacks: SYN floods, amplification, botnets, and DDoS mitigation strategies. Exam focus: separate DoS from DDoS and volumetric from protocol-based attacks, and know exactly what a SYN flood exhausts. Amplification questions (DNS/NTP reflection) test whether you can identify the traffic asymmetry that makes them work.

⚠️ Important Disclaimer: These practice questions are original study material created by CEHStudy for educational purposes. They are NOT EC-Council exam questions and do NOT replicate the actual exam. CEHStudy is not affiliated with or endorsed by EC-Council.

Question 1: The primary difference between a DoS and a DDoS attack is:

Answer: A — Many distributed sources make DDoS far harder to block — blocking one IP stops a DoS, not a DDoS.

Question 2: A SYN flood fills the target's connection table with:

Answer: D — SYNs are sent but never acknowledged, so slots sit waiting until legitimate users can't connect — mitigated by SYN cookies and rate limiting.

Question 3: A Smurf attack sends:

Answer: B — Every host on the broadcast domain replies to the 'victim' — amplification equals the number of hosts; modern networks block directed broadcast.

Question 4: Slowloris is a Layer 7 attack because it:

Answer: C — It consumes application-level resources (connections), not bandwidth — so it needs little traffic and evades volumetric defenses.

Question 5: DNS amplification attacks work by:

Answer: A — Mitigations: disable open resolvers, source validation (BCP38/BCP84), and upstream scrubbing.

Question 6: Which category of DDoS attack includes SYN floods and Smurf?

Answer: A — Protocol attacks exhaust connection state and resources (SYN flood, Smurf, Ping of Death); volumetric uses bandwidth floods; L7 targets app logic (Slowloris).

Question 7: A 'Ping of Death' attack:

Answer: C — Legacy and IoT stacks still mishandle reassembly of giant fragmented echoes — mostly patched in modern OSes.

Question 8: LOIC and HOIC are examples of:

Answer: A — 'Low/High Orbit Ion Cannon' generate simple floods — the same engines behind commercial 'booter/stresser' abuse services.

Question 9: Anycast networking helps mitigate DDoS by:

Answer: D — Attack volume is spread thin across the anycast footprint, and nearby edge locations absorb regional floods.

Question 10: Fraggle attacks are similar to Smurf but use:

Answer: C — Fraggle = the UDP variant of Smurf: broadcast UDP echo with spoofed victim source, amplifying replies at the target.

Related Glossary Terms

Continue Your CEH v13 Prep

Frequently Asked Questions

How many CEH v13 Denial-of-Service Attacks practice questions are on this page?

This page includes 10 original multiple-choice practice questions for CEH v13 Module 10 (Denial-of-Service Attacks). Each question includes a detailed explanation of the correct answer and why the other options are wrong. The full CEHStudy question bank covers all 20 modules with 200+ questions — see the practice hub at https://cehstudy.com/ceh-practice-questions/ for every module.

What does CEH v13 Module 10 (Denial-of-Service Attacks) cover?

Volume, protocol, and application-layer attacks: SYN floods, amplification, botnets, and DDoS mitigation strategies. These are the same topics tested under this module on the EC-Council 312-50 exam. Pair this quiz with our free Module 10 flashcards at https://cehstudy.com/ceh-v13/module-10/ to close any gaps.

Are these real CEH exam questions?

No. Every question on CEHStudy is original study material written for exam preparation. They match the style, difficulty, and domain coverage of the actual CEH v13 exam but are not leaked or reproduced EC-Council questions.

How should I use this Denial-of-Service Attacks quiz for exam prep?

Answer all 10 questions without peeking at explanations, then click "Show My Score". Review every explanation — especially the ones you missed — and re-test those topics with our free CEH flashcards. Aim for 80% or higher on module quizzes before scheduling the exam.

Where do I find CEH Denial-of-Service Attacks flashcards?

Our free flashcard app covers all 20 CEH v13 modules including Module 10 (Denial-of-Service Attacks). Visit the CEH flashcards page at https://cehstudy.com/ or the Module 10 page at https://cehstudy.com/ceh-v13/module-10/. No account or sign-up required.