QuestionQ239

Network Design

Which outcome of applying ingress filtering to prevent spoofed addresses in a network design is true?

  • A It filters RFC 1918 IP addresses.
  • B It protects the network infrastructure against spoofed DDoS attacks.
  • C It reduces the effectiveness of DDoS attacks when associated with DSCP remarking to Scavenger.
  • D It classifies bogon traffic and remarks it with DSCP bulk.
Explanation

Ingress filtering drops traffic with invalid or spoofed source addresses, limiting DDoS attacks that rely on source-address spoofing and protecting the network implementing the filter. RFC 3704: Ingress Filtering for Multihomed Networks

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!