Certified Ethical Hacker (CEH v12) — Question 168

A well-resourced attacker intends to launch a highly disruptive DDoS attack against a major online retailer. The attacker aims to exhaust all the network resources while keeping their identity concealed. Their method should be resistant to simple defensive measures such as IP-based blocking. Based on these objectives, which of the following attack strategies would be most effective?

Answer options

Correct answer: B

Explanation

The correct answer is B because leveraging a botnet for a Pulse Wave attack allows for sustained high-volume traffic that can bypass simple defenses, maintaining anonymity. Options A, C, and D are less effective as they either rely on single-source attacks or can be mitigated by standard defensive techniques like rate limiting or IP blocking.