nerdexam
EC-Council

312-49 · Question #364

You work as a penetration tester for Hammond Security Consultants. You are currently working on a contract for the state government of California. Your next step is to initiate a DoS attack on their n

The correct answer is B. List weak points on their network. During a penetration test, initiating a controlled DoS attack helps identify weak points in the network - such as services that crash, systems that fail to implement rate limiting, or infrastructure that lacks DoS mitigation (e.g., no IPS, no load balancing, no traffic scrubbing)

Submitted by skyler.x· Apr 18, 2026Network Forensics

Question

You work as a penetration tester for Hammond Security Consultants. You are currently working on a contract for the state government of California. Your next step is to initiate a DoS attack on their network. Why would you want to initiate a DoS attack on a system you are testing?

Options

  • ADemonstrate that no system can be protected againstDoS attacks
  • BList weak points on their network
  • CShow outdatedeQuipment so it can be replaced
  • DUse attack as a launching point to penetrate deeper into the network

How the community answered

(19 responses)
  • B
    95% (18)
  • C
    5% (1)

Explanation

During a penetration test, initiating a controlled DoS attack helps identify weak points in the network - such as services that crash, systems that fail to implement rate limiting, or infrastructure that lacks DoS mitigation (e.g., no IPS, no load balancing, no traffic scrubbing). The goal is not to cause damage but to document vulnerabilities so the client can remediate them. A legitimate pen test DoS is scoped and authorized, and its findings are reported to improve the client's defenses.

Topics

#Penetration Testing#DoS Attack#Network Vulnerability#Security Assessment

Community Discussion

No community discussion yet for this question.

Full 312-49 Practice