nerdexam
EC-Council

312-39 · Question #37

You are a SOC analyst on duty during a high-severity incident involving a DDoS attack targeting your organization's e-commerce platform. The attack disrupts online transactions. Using SIEM tools and…

The correct answer is B. Neutralizing handlers. “Neutralizing handlers” is the best match because it focuses on disrupting the botnet’s command- and-control layer that coordinates the attack. In classic botnet terminology, handlers (or C2 nodes) issue instructions to compromised hosts. If you can block, sinkhole, or…

Security Incident Response

Question

You are a SOC analyst on duty during a high-severity incident involving a DDoS attack targeting your organization’s e-commerce platform. The attack disrupts online transactions. Using SIEM tools and packet capture systems, you identify unusual traffic patterns and trace activity back to command- and-control (C2) servers directing a botnet. Your goal is to recommend an eradication strategy that will sever the attackers’ control over infected devices and halt the attack. Which strategy should your team implement?

Options

  • ARate limiting
  • BNeutralizing handlers
  • CBlocking potential attacks
  • DDisabling botnets

How the community answered

(53 responses)
  • A
    9% (5)
  • B
    81% (43)
  • C
    4% (2)
  • D
    6% (3)

Explanation

“Neutralizing handlers” is the best match because it focuses on disrupting the botnet’s command- and-control layer that coordinates the attack. In classic botnet terminology, handlers (or C2 nodes) issue instructions to compromised hosts. If you can block, sinkhole, or otherwise disrupt communication to those controlling nodes, you reduce the adversary’s ability to direct traffic and sustain the DDoS. Rate limiting is a useful mitigation to reduce immediate impact on your services, but it does not sever attacker control; it is more a resilience measure than eradication. “Blocking potential attacks” is too generic and describes a broad defensive posture rather than a specific botnet-focused eradication action. “Disabling botnets” is an outcome, but it is not a precise operational strategy in the way “neutralizing handlers” is; disabling a botnet often requires a combination of takedowns, sinkholing, upstream provider coordination, and endpoint remediation- activities that are commonly operationalized by targeting the handler/C2 infrastructure. From a SOC standpoint, this also aligns with coordinated response: implement network blocks, collaborate with ISP/CDN, and use threat intel to identify additional C2 endpoints while continuing service-level

Topics

#DDoS eradication#botnet C2 neutralization#incident response#handler takedown

Community Discussion

No community discussion yet for this question.

Full 312-39 Practice