ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
An e-commerce company hosts its public marketing site on a single web server in the on-premises DMZ. Over the past month, volumetric DDoS floods have saturated the organization's Internet circuit, taking the site and internal services offline. Management needs a cost-effective mitigation that requires minimal changes to the existing hosting arrangement and should also improve latency for legitimate visitors. Which solution best meets these goals?
Upgrade the Internet circuit bandwidth and add a second on-premises web server behind a local load balancer.
Configure perimeter router ACLs to allow only TCP ports 80 and 443 to the web server.
Deploy a globally distributed content delivery network in front of the web server to cache content and absorb large traffic spikes.
Install a stateful packet-filtering firewall that drops traffic to the web server when utilization exceeds a threshold.
Placing the site behind a content delivery network (CDN) moves traffic termination to a globally distributed edge network. The CDN caches static content and uses anycast to absorb large volumes of malicious traffic, protecting the limited on-premises bandwidth while simultaneously accelerating delivery for legitimate users. A stateful firewall alone cannot handle link-flooding attacks, larger circuits and extra servers increase cost but still leave the single ISP link vulnerable, and simple ACLs on the perimeter router do not stop volumetric floods that overwhelm bandwidth before filtering can occur.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Content Delivery Network (CDN)?
Open an interactive chat with Bash
How does Anycast routing work in a CDN?
Open an interactive chat with Bash
What are volumetric DDoS attacks?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Network and Communication Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .