nerdexam
CompTIA

CAS-003 · Question #487

A network administrator is concerned about a particular server that is attacked occasionally from hosts on the Internet. The server is not critical; however, the attacks impact the rest of the…

The correct answer is C. Advertise a /32 route to the ISP to initiate a remotely triggered black hole, which will discard. The key constraints are: the ISP is slow to respond, the administrator needs immediate self-service mitigation, and the ISP has pre-agreed to accept a small network route advertised with a specific BGP community string. This describes Remotely Triggered Black Hole (RTBH)…

Enterprise Security Operations

Question

A network administrator is concerned about a particular server that is attacked occasionally from hosts on the Internet. The server is not critical; however, the attacks impact the rest of the network. While the company's current ISP is cost effective, the ISP is slow to respond to reported issues. The administrator needs to be able to mitigate the effects of an attack immediately without opening a trouble ticket with the ISP. The ISP is willing to accept a very small network route advertised with a particular BGP community string. Which of the following is the BESRT way for the administrator to mitigate the effects of these attacks?

Options

  • AUse the route protection offered by the ISP to accept only BGP routes from trusted hosts on
  • BWork with the ISP and subscribe to an IPS filter that can recognize the attack patterns of the
  • CAdvertise a /32 route to the ISP to initiate a remotely triggered black hole, which will discard
  • DAdd a redundant connection to a second local ISP, so a redundant connection is available for

How the community answered

(31 responses)
  • A
    10% (3)
  • B
    23% (7)
  • C
    65% (20)
  • D
    3% (1)

Explanation

The key constraints are: the ISP is slow to respond, the administrator needs immediate self-service mitigation, and the ISP has pre-agreed to accept a small network route advertised with a specific BGP community string. This describes Remotely Triggered Black Hole (RTBH) routing. By advertising a /32 host route (the most specific route for a single IP) tagged with the agreed-upon BGP community string, the administrator instructs the ISP's routers to null-route all traffic destined for the attacked server at the ISP's edge-stopping the attack upstream before it saturates the university's link. No ticket is required because the ISP already agreed to honor this advertisement. BGP route filtering (A) does not mitigate a volumetric attack. An IPS subscription (B) takes time to set up. A redundant ISP (D) does not stop the attack; the traffic simply follows the server to the new link.

Topics

#BGP black hole routing#DDoS mitigation#remotely triggered blackhole#ISP coordination

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice