An attacker sends millions of small DNS queries to a CDN's authoritative nameservers to exhaust UDP processing capacity. Which mitigation is most appropriate?
-
A
Increase DNS TTL to reduce query volume
-
B
Deploy anycast DNS with rate limiting and response rate limiting (RRL)
-
C
Switch to TCP-only DNS
-
D
Add more A records for the origin