Best Defense Against DDoS Attacks in Enterprise Networks?
Which of the following is the BEST defense against distributed denial of service (DDoS) attacks?
Community Votes
50% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests architectural availability planning versus tactical perimeter controls, with candidates often trapping themselves by choosing firewall configuration over inherent network resilience.
This CISM question evaluates how to architecturally protect critical services from Distributed Denial of Service (DDoS) disruptions. While perimeter filtering helps, experts and community consensus agree that network redundancy and multiple routing paths provide the most resilient defense for maintaining availability.
Option D (Well-configured routers and firewalls) is frequently chosen because it represents a tangible security control, but it fails to address volumetric saturation that overwhelms even optimized perimeter devices during sustained DDoS campaigns.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
ISACA prioritizes business continuity and system availability when evaluating DDoS defenses. Multiple and redundant network paths ensure that traffic can be rerouted around congested or attacked segments, preserving uptime even during volumetric floods. This architectural resilience directly supports the CIA triad’s availability requirement, making it the most robust enterprise-level strategy among the choices.Why the Other Options Are Wrong
Regular patching addresses vulnerability management but does nothing to mitigate traffic exhaustion. Intruder-detection lockouts are reactive mechanisms that can be easily triggered by legitimate users or spoofed source IPs during a flood. Well-configured routers and firewalls provide valuable filtering, yet they remain vulnerable to bandwidth saturation and protocol exploits that overwhelm inspection engines regardless of configuration quality.Community Comment Notes
As discussed in the community, Comment 1 argues for perimeter filtering while Comment 4 emphasizes architectural resilience. Comment 5 correctly notes that layered defense is ideal, but CISM isolates the single best strategic choice. The consensus ultimately favors redundancy because it guarantees availability when perimeter devices face saturation.Official Reference
Exam Strategy
When evaluating DDoS defenses in CISM, prioritize solutions that preserve business availability and continuity over pure access control mechanisms. Always ask which option provides inherent resilience rather than temporary mitigation.
Frequently Asked Questions
Why isn't D: Well-configured routers and firewalls the best defense?
Perimeter devices can be overwhelmed by volumetric attacks before filtering rules trigger. Redundant paths provide inherent architectural resilience that firewalls alone cannot guarantee.
How does CISM prioritize DDoS mitigation strategies?
CISM focuses on business impact and availability. Solutions that maintain uptime through load distribution and failover take precedence over reactive or purely technical controls.
Related Analysis
Practice All CISM Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISM Practice Test →