nerdexam
CompTIA

CAS-003 · Question #386

Users have been reporting unusual automated phone calls, including names and phone numbers, that appear to come from devices internal to the company. Which of the following should the systems…

The correct answer is B. change the settings on the phone system to use SIP-TLS. The scenario describes VoIP (Voice over IP) caller ID spoofing, where an attacker is intercepting unencrypted SIP (Session Initiation Protocol) signaling traffic and forging internal caller identities. SIP-TLS encrypts the SIP signaling channel using TLS, preventing attackers…

Technical Integration of Enterprise Security

Question

Users have been reporting unusual automated phone calls, including names and phone numbers, that appear to come from devices internal to the company. Which of the following should the systems administrator do to BEST describes this problem?

Options

  • AAdd an ACL to the firewall to block VoIP.
  • Bchange the settings on the phone system to use SIP-TLS.
  • CHave the phones download new configuration over TFTP.
  • DEnable QoS configuration on the phone VLAN

How the community answered

(34 responses)
  • A
    6% (2)
  • B
    76% (26)
  • C
    3% (1)
  • D
    15% (5)

Explanation

The scenario describes VoIP (Voice over IP) caller ID spoofing, where an attacker is intercepting unencrypted SIP (Session Initiation Protocol) signaling traffic and forging internal caller identities. SIP-TLS encrypts the SIP signaling channel using TLS, preventing attackers from eavesdropping on or manipulating call setup messages, which stops the spoofing of internal names and numbers. Blocking VoIP at the firewall (A) would eliminate the company's VoIP service entirely. Having phones download configuration over TFTP (C) is actually a security risk because TFTP is unencrypted and could expose configuration data to interception. Enabling QoS on the phone VLAN (D) prioritizes traffic quality but provides no security protection against spoofing.

Topics

#VoIP security#SIP-TLS#call spoofing#vishing

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice