šŸ”„ 40% Off Crucial Exams Memberships — This Week Only

2 days, 9 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

An online retailer hosts its e-commerce site in its on-premises data center behind a 1 Gbps Internet circuit and a stateful firewall that can forward up to 500 Mbps. Over the past week, attackers have launched UDP reflection floods that completely saturate the circuit, making the site unreachable. Management requests a mitigation that preserves availability while requiring no significant changes to internal network equipment. Which approach best satisfies these requirements?

  • Increase the SYN backlog queue on each web server to handle more half-open TCP connections.

  • Enable port-security on core switches to limit the number of source MAC addresses allowed on each port.

  • Route inbound traffic through a cloud-based DDoS scrubbing service or CDN that filters attacks at distributed edge nodes before forwarding clean traffic to the data center.

  • Replace the existing firewall with a 10 Gbps model and configure it to drop all inbound UDP packets.

ISC2 Systems Security Certified Practitioner (SSCP)
Network and Communication Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot