Best Defense Against DDoS Attacks in Enterprise Networks?

Answer Correct answer: B — Implement multiple and redundant network paths to distribute traffic load and maintain service availability during sustained DDoS flooding.

Which of the following is the BEST defense against distributed denial of service (DDoS) attacks?

  1. Regular patching
  2. Multiple and redundant paths Correct Answer
  3. Intruder-detection lockout
  4. Well-configured routers and firewalls

Community Votes

B
50%
D
50%

50% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests architectural availability planning versus tactical perimeter controls, with candidates often trapping themselves by choosing firewall configuration over inherent network resilience.

This CISM question evaluates how to architecturally protect critical services from Distributed Denial of Service (DDoS) disruptions. While perimeter filtering helps, experts and community consensus agree that network redundancy and multiple routing paths provide the most resilient defense for maintaining availability.

Option D (Well-configured routers and firewalls) is frequently chosen because it represents a tangible security control, but it fails to address volumetric saturation that overwhelms even optimized perimeter devices during sustained DDoS campaigns.

Community Discussion (5 comments)

SHERLOCKAWS 👍 1 Selected: B
Answer is B. Multiple and redundant paths. Because DDoS attacks aim to flood and overwhelm systems or networks with traffic from many sources. The best defense is to have resilience and redundancy built into your network architecture. Multiple and redundant paths (like through CDNs, load balancers, and geographically dispersed servers) help absorb or reroute malicious traffic, keeping services up. Regarding D.Well-configured routers and firewalls. This is an expected basic line of defense, especially with access control lists (ACLs) or rate-limiting. But they can be also overwhelmed in large-scale DDoS attacks without the redundancy and capacity offered by option B.
eshah 👍 2 Selected: B
Best way is to have multiple and redundant path for mitigating DDOS
mdmdmd 👍 1 Selected: D
It can be a well-defense layered strategy
Raj91188 👍 2 Selected: D
Properly configured routers and firewalls can filter out malicious traffic and help mitigate the effects of a DDoS attack
Infosecnerd 👍 3
D: Well-configured routers and firewalls are the best defense against distributed denial of service (DDoS) attacks. These network security devices can help filter and block malicious traffic, manage network traffic more effectively, and mitigate the impact of DDoS attacks by controlling and limiting the volume of incoming traffic.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

ISACA prioritizes business continuity and system availability when evaluating DDoS defenses. Multiple and redundant network paths ensure that traffic can be rerouted around congested or attacked segments, preserving uptime even during volumetric floods. This architectural resilience directly supports the CIA triad’s availability requirement, making it the most robust enterprise-level strategy among the choices.

Why the Other Options Are Wrong

Regular patching addresses vulnerability management but does nothing to mitigate traffic exhaustion. Intruder-detection lockouts are reactive mechanisms that can be easily triggered by legitimate users or spoofed source IPs during a flood. Well-configured routers and firewalls provide valuable filtering, yet they remain vulnerable to bandwidth saturation and protocol exploits that overwhelm inspection engines regardless of configuration quality.

Community Comment Notes

As discussed in the community, Comment 1 argues for perimeter filtering while Comment 4 emphasizes architectural resilience. Comment 5 correctly notes that layered defense is ideal, but CISM isolates the single best strategic choice. The consensus ultimately favors redundancy because it guarantees availability when perimeter devices face saturation.

Official Reference

Exam Strategy

When evaluating DDoS defenses in CISM, prioritize solutions that preserve business availability and continuity over pure access control mechanisms. Always ask which option provides inherent resilience rather than temporary mitigation.

Frequently Asked Questions

Why isn't D: Well-configured routers and firewalls the best defense?

Perimeter devices can be overwhelmed by volumetric attacks before filtering rules trigger. Redundant paths provide inherent architectural resilience that firewalls alone cannot guarantee.

How does CISM prioritize DDoS mitigation strategies?

CISM focuses on business impact and availability. Solutions that maintain uptime through load distribution and failover take precedence over reactive or purely technical controls.

Related Analysis

Practice All CISM Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISM Practice Test →

← Back to CISM Study Guide