Question: On a Saturday afternoon, external users start having problems accessing the organizations public websites. Over the next hour, the problem worsens to the point where
On a Saturday afternoon, external users start having problems accessing the organizations public websites. Over the next hour, the problem worsens to the point where nearly every access attempt fails. Meanwhile, a member of the organizations networking staff responds to alerts from an Internet border router and determines that the organizations Internet bandwidth is being consumed by an unusually large volume of (UDP) packets to and from both the organizations public DNS servers. Analysis of the traffic shows that the DNS servers are receiving high volumes of requests from a single external IP address. Also, all the DNS requests from that address come from the same source port.
1. Would the organization consider this activity to be an incident? If so, which of the organizations policies does this activity violate?
2. What measures are in place to attempt to prevent this type of incident from occurring or to limit its impact?
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
