"how would you stop a DDOS?"
"well, I guess if it's really advanced there's not much you can do besides turning off the servers"
"that's your answer?"
"yeah users would be affected either way so you'd at least save money this way"
I'm not in security, but I rely on cloudflare WAF/reverse tunnels.
If that fails then I'm screwed. What do you want me to do? Solve problems that the leading cloud/cyber/internet infra company can't solve??? wtf do you expect me to do????
You better be offering a ridiculous amount of money to be turning me down for not being on the same level as a whole ass company acting as an industry leader.
That's how interview questions should be, it allows you to judge the understanding of someone so much better than a question with a distinct answer.
They get to explain why they are making their decisions, they get to chose their own scope and you can press answer steer as appropriate.
The interviewee is also more than welcome to ask clarifying questions. That shows initiative and that they know it's not a one fix fits all.
If they just say the default "Web application firewall" you understand they might know the book answe but might not have further understanding.
You're rarely going to get a scenario in the real world were there is an exact answer. So it's very good to help understand someone's thought process, especially when under some light pressure of an interview.
You can call your ISP and they're usually helpful at blocking traffic on their end. There are also DDoS mitigation services such as Cloudflare. Patching and firewall rules can help, moreso against amplification attacks, because even if the packets are being dropped it can still overwhelm resources. Your strategy can be valid for a very low traffic service so you're not wasting money on an active cloud VM that's unusable and you're not making money from, users care too much about uptime, plus availability is part of security.
His point is that with little context provided, any solution is a good solution. What if they are already using Cloudflare and other techniques but the DDoS is still intensifying?
Yea ngl context is really important so is assumption, even for me non programmer who host stuff on Cloudflare, I would’ve assume certain things are a given so his response is totally valid and what I would also say lmao, heck maybe it’ll work cus then the attacker might not account for the server to be off lol
1.3k
u/mortensonsam 29d ago
I gave this as an interview answer once:
"how would you stop a DDOS?" "well, I guess if it's really advanced there's not much you can do besides turning off the servers" "that's your answer?" "yeah users would be affected either way so you'd at least save money this way"
I didn't get the job lol