QuestionQ6

Threat Hunting Techniques

A cybersecurity team discovers an increase in DNS amplification attacks. The team wants to prevent an attack and reviews the current configurations. The company has a load balancer to manage network traffic and a DMZ containing important assets. Source IP verification for DNS requests is configured on the servers.

Which additional action should the team take to mitigate similar attacks?

Explanation

DNS amplification attacks exploit recursive DNS services by sending queries with forged victim source addresses, causing the server to send amplified responses to the victim. Disabling recursion on authoritative name servers prevents those servers from functioning as open recursive resolvers and being abused for reflection/amplification attacks.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!