Question 1
A UDP reflection attack saturates an emergency dispatch center's provider-to-customer access link. The targeted IPv4 gateway also terminates essential HTTPS sessions and IPsec NAT traversal on UDP 4500; both services are failing. Captures confirm that the entire flood consists of unfragmented UDP packets with source port 123, and no legitimate traffic to this address uses that source port. An authorized FlowSpec controller can install filters at every attack ingress before the saturated link. Which immediate action restores capacity while preserving both legitimate services?
Show answer & explanation
Correct answer: B - Install an upstream FlowSpec discard rule matching destination gateway /32, UDP, and source port 123.