CAS-002 · Question #553
Wireless users are reporting issues with the company's video conferencing and VoIP systems. The security administrator notices DOS attacks on the network that are affecting the company's VoIP system…
The correct answer is C. Configure 802.11e on the network D. Update the firewall managing the SIP servers. Mitigating VoIP DoS attacks requires QoS prioritization for voice traffic via 802.11e and firewall hardening to protect the SIP signaling servers.
Question
Wireless users are reporting issues with the company's video conferencing and VoIP systems. The security administrator notices DOS attacks on the network that are affecting the company's VoIP system (i.e. premature call drops and garbled call signals). The security administrator also notices that the SIP servers are unavailable during these attacks. Which of the following security controls will MOST likely mitigate the VoIP DOS attacks on the network? (Select TWO).
Options
- AConfigure 802.11b on the network
- BConfigure 802.1q on the network
- CConfigure 802.11e on the network
- DUpdate the firewall managing the SIP servers
- EUpdate the HIDS managing the SIP servers
How the community answered
(27 responses)- A4% (1)
- B19% (5)
- C70% (19)
- E7% (2)
Why each option
Mitigating VoIP DoS attacks requires QoS prioritization for voice traffic via 802.11e and firewall hardening to protect the SIP signaling servers.
802.11b is an older 2.4 GHz wireless standard limited to 11 Mbps with no QoS capabilities, and deploying it would degrade network performance rather than protect VoIP traffic.
802.1q defines VLAN trunking and tagging for network segmentation, which can improve isolation but does not provide QoS prioritization or actively mitigate DoS traffic targeting VoIP infrastructure.
IEEE 802.11e introduces QoS mechanisms (EDCA/HCCA) to wireless networks that prioritize time-sensitive traffic such as VoIP and video conferencing, reducing the impact of congestion-based DoS attacks that cause dropped calls and garbled audio.
Updating the firewall managing the SIP servers allows administrators to add rate-limiting rules and SIP-aware filtering that block or throttle DoS traffic targeting the SIP signaling plane, directly addressing the server unavailability observed during the attacks.
A Host-based IDS (HIDS) monitors and alerts on suspicious activity on the SIP server but does not actively block or prevent inbound DoS traffic, making it a detection tool rather than a mitigation control.
Concept tested: VoIP DoS mitigation with 802.11e QoS and SIP firewall controls
Source: https://www.cisco.com/c/en/us/support/docs/voice/voice-quality/14081-voip-secur.html
Topics
Community Discussion
No community discussion yet for this question.