CAS-003 · Question #483
A university's help desk is receiving reports that Internet access on campus is not functioning. The network administrator looks at the management tools and sees the 1Gbps Internet is completely…
The correct answer is D. The ISP engineer should begin refusing network connections to the web server immediately to. The university's 1Gbps link is fully saturated with inbound (ingress) attack traffic, making it unusable for legitimate users. The fastest and most appropriate upstream mitigation is for the ISP engineer to immediately begin refusing (rate-limiting or blocking) new network…
Question
A university's help desk is receiving reports that Internet access on campus is not functioning. The network administrator looks at the management tools and sees the 1Gbps Internet is completely saturated with ingress traffic. The administrator sees the following output on the Internet router:
The administrator calls the university's ISP for assistance, but it takes more than four hours to speak to a network engineer who can resolve the problem. Based on the information above, which of the following should the ISP engineer do to resolve the issue?
Exhibit
Options
- AThe ISP engineer should null route traffic to the web server immediately to restore Internet
- BA university web server is under increased load during enrollment. The ISP engineer should
- CThe ISP engineer should immediately begin blocking IP addresses that are attacking the web
- DThe ISP engineer should begin refusing network connections to the web server immediately to
How the community answered
(31 responses)- A3% (1)
- B3% (1)
- C10% (3)
- D84% (26)
Explanation
The university's 1Gbps link is fully saturated with inbound (ingress) attack traffic, making it unusable for legitimate users. The fastest and most appropriate upstream mitigation is for the ISP engineer to immediately begin refusing (rate-limiting or blocking) new network connections destined for the targeted web server at the ISP's edge. This stops the flood before it consumes the university's link while preserving bandwidth for other campus traffic. Null routing the server's IP (A) would stop the attack but also completely eliminates legitimate access. Dismissing it as enrollment load (B) ignores the attack. Blocking individual attacking IPs (C) is ineffective against a distributed attack with many source addresses and is operationally slow. Acting at the connection level upstream is the most effective immediate measure.
Topics
Community Discussion
No community discussion yet for this question.
