Cisco CCNP Security Core (SCOR) 350-701Visibility and EnforcementHard

A network security engineer is implementing a distributed denial-of-service (DDoS) protection solution for an organization's public-facing web services. The solution must be capable of identifying and mitigating volumetric, protocol, and application-layer DDoS attacks without impacting legitimate user traffic. Which deployment model for a DDoS protection system is generally considered most effective for meeting these requirements at scale?

  1. AOn-premises appliance-based DDoS mitigation.
  2. BCloud-based DDoS scrubbing service.
  3. CFirewall-based SYN flood protection.
  4. DRouter-based rate limiting and ACLs.
Show answer & explanation

Correct answer: B. Cloud-based DDoS scrubbing service.

Cloud-based DDoS scrubbing services are inherently scalable to handle massive volumetric attacks, can analyze and filter various attack types (volumetric, protocol, application-layer) before they reach the organization's network, and are designed to minimize impact on legitimate traffic. On-premises solutions often lack the bandwidth and processing power for large-scale attacks.

Why the other options are wrong

  • A. On-premises appliances can mitigate some DDoS attacks but are often overwhelmed by volumetric attacks, leading to saturation of the internet link.
  • C. Firewall-based SYN flood protection is effective against a specific type of attack but is insufficient for comprehensive DDoS protection across all layers.
  • D. Router-based rate limiting and ACLs are basic and can only provide limited protection against sophisticated or large-scale DDoS attacks.

Cloud-based DDoS Scrubbing Service

A service offered by a third-party provider that diverts an organization's internet traffic during a DDoS attack, 'scrubs' or cleans the malicious traffic, and then forwards only legitimate traffic back to the organization's network.

  • Leverages provider's massive bandwidth to absorb attacks.
  • Protects against volumetric, protocol, and application-layer attacks.
  • Minimizes impact on legitimate traffic and organizational infrastructure.
  • Always-on or on-demand deployment models.

Memory trick: To weather the DDoS storm, go to the cloud's big umbrella.

More Visibility and Enforcement questions