Code RoomVolumetric DNS amplification
MediumPrep Room Coding #2517

Volumetric DNS amplification

On-callNetworking & APIsMid–Senior~35 min

Your authoritative DNS and a couple of edge POPs go unreachable. The network dashboard shows inbound traffic at 380 Gbps — 50x normal — almost entirely UDP packets on source port 53 with spoofed sources, hitting your edge link to saturation. Your upstream transit provider just paged you about link congestion. No application servers are unhealthy; the problem is pure link saturation upstream of your boxes. It started 8 minutes ago with no deploy or product change. How do you triage and mitigate this volumetric attack?

What a strong answer looks like

Stop the bleeding first (mitigate), then form hypotheses from real signals. Separate root cause from symptom, communicate status as you go, and close with what prevents a repeat.

0:00 of about 35 min
Which questions mattered is sealed until you submit. Telling you now would just be handing over the edge cases.