Your question is DDoS Attack: DNS and Amplification. Take a moment with it on the right.
Talk me through your thinking if you like. When you're confident, submit your answer and I'll grade it like a real screen (7/10 or better passes).
How do you use DNS queries to launch a DDoS attack, and which underlying protocol makes this amplification attack possible?
Asked in the Technical Phone Screen stage. This technical question covers DNS amplification attacks. The expected protocol answer was UDP, because it is stateless and permits IP spoofing.
Discuss the attack flow at a high level, explain the amplification mechanism, identify the relevant trust boundaries, and recommend practical detection and mitigation controls without providing an operational attack recipe.