I think the question omitted the fact that the attack is coming from outside the network. The drop RFC 1918 request is to tell the ISP to block all traffic from spoofed Private IP addresses, which I thought all ISPs did already. I assumed it was a malware infected workstation inside the network and choose the ACL Firewall rule as the answer to block all traffic from the infected workstation. I don't like the question.