exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 464 discussion

Actual exam question from ISC's CISSP
Question #: 464
Topic #: 1
[All CISSP Questions]

An organization has experienced multiple distributed denial-of-service (DDoS) attacks in recent months that have impact of their public-facing web and e-commerce sites that were previously all on-premises. After an analysis of the problems, the network engineers have recommended that the organization implement additional name service providers and redundant network paths. What is another recommendation that helps ensure the future availability of their web and e-commerce sites?

  • A. Move all cloud-based operations back to on-premises to mitigate attacks.
  • B. Move all websites to a new location.
  • C. Review current detection strategies and employ signature-based techniques.
  • D. Review the service-level agreements (SLA) with their cloud service providers.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Highly Voted 1 year, 9 months ago
D. The cloud service provider such as Azure or AWS can mitigate these attacks: https://www.stormit.cloud/blog/cloud-ddos-protection-how-to-mitigate-all-risks/
upvoted 6 times
Highly Voted 1 year, 12 months ago
Going with C Reviewing service-level agreements (SLAs) with cloud service providers is also important, but it is not directly related to the goal of ensuring the future availability of their web and e-commerce sites in the face of DDoS attacks.
upvoted 6 times
1 year, 10 months ago
C is correct
upvoted 2 times
9 months, 2 weeks ago
Agreed. C
upvoted 1 times
Most Recent 7 months ago
Selected Answer: D
C. While improving detection strategies is important, relying solely on signature-based techniques may not be effective against all DDoS attacks, especially sophisticated ones that can vary widely in form and signature. D. SLAs should include guarantees for uptime, support response times, and mitigation measures for DDoS attacks. If the current SLAs are insufficient, the organization might consider negotiating better terms or seeking additional protections such as DDoS mitigation services provided by the cloud service provider.
upvoted 1 times
9 months, 2 weeks ago
Selected Answer: C
C will better help ensure avialability of the web app.
upvoted 1 times
11 months, 2 weeks ago
Selected Answer: D
Here's why: SLAs define the services offered and the level of commitment from the cloud provider. In the context of DDoS attacks, the SLA should specify how the provider will handle such attacks and what level of uptime they guarantee during such events. Reviewing the SLA can help identify any gaps in protection. For example, the SLA might not cover certain types of DDoS attacks or might have limitations on how much mitigation they offer. Based on the review, the organization can negotiate with the cloud provider to improve their DDoS protection mechanisms or potentially explore alternative providers with more robust DDoS mitigation capabilities.
upvoted 1 times
11 months, 2 weeks ago
C. Signature-based techniques: While signature-based detection can be helpful for known attack patterns, it might not be effective against novel DDoS attacks. A more comprehensive approach that combines signature-based with anomaly-based detection is often recommended.
upvoted 1 times
1 year, 1 month ago
Answer C: Review current detection strategies and employ signature-based techniques. https://ieeexplore.ieee.org/abstract/document/9511420 https://www.researchgate.net/profile/Mohammed-Alenezi-5/publication/352312016_Methodologies_for_detecting_DoSDDoS_attacks_against_network_servers/links/60c31c9ba6fdcc2e6131a793/Methodologies-for-detecting-DoS-DDoS-attacks-against-network-servers.pdf If the cloud provider was a CDN to prevent DDOS attacks, they wouldn't have "experienced multiple distributed denial-of-service (DDoS) attacks" so reviewing the SLA wont address the problem.
upvoted 1 times
1 year, 3 months ago
C. Review current detection strategies and employ signature-based techniques Reviewing detection strategies and employing signature-based techniques is a more direct and effective measure to address DDoS attacks and enhance the availability of web and e-commerce sites. Signature-based techniques can help identify known attack patterns and allow for a more proactive response.
upvoted 1 times
1 year, 3 months ago
While reviewing service-level agreements (SLAs) with cloud service providers is important, it is not directly related to the goal of ensuring the future availability of web and e-commerce sites in the face of DDoS attacks. On the other hand, "C. Review current detection strategies and employ signature-based techniques" is a more relevant recommendation
upvoted 1 times
1 year, 3 months ago
Selected Answer: D
I think it's D. Supporters of D, please make sure to cast your votes. Switch to voting comments and just select your choice, okay?
upvoted 5 times
1 year, 4 months ago
D is the answer: Reviewing SLAs will allow assessing and potentially strengthening the uptime and response commitments from cloud providers. SLAs can stipulate availability metrics, response times, mitigation capabilities, and penalties for the provider. This helps contractually ensure and incentivize availability of the hosted services during a DDoS attack. Signature-based detection by itself has limited ability to mitigate DDoS attacks: -DDoS attacks rely on flooding infrastructure with high volumes of traffic from distributed sources. -This doesn't necessarily rely on known attack signatures. -Signatures focus on detecting specific known malicious payloads or behavior patterns. -DDoS can use varying protocols and payload patterns. -The high volume and distributed nature of DDoS makes signature analysis technically challenging to keep up with traffic speed and volume.
upvoted 2 times
1 year, 9 months ago
Selected Answer: C
C is correct
upvoted 4 times
Community vote distribution
A (35%)
C (25%)
B (20%)
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

Loading ...
Someone Bought Contributor Access for:
London, 1 minute ago