nerdexam
(ISC)2

CISSP · Question #879

A security engineer is conducting an audit of an organization's Voice over Internet Protocol (VoIP) phone network due to a large increase in charges from their phone provider. The engineer discovers u

The correct answer is B. Toll fraud. The scenario describes unauthorized external parties connecting to a VoIP server and placing numerous unauthorized calls globally, resulting in increased charges. This attack, which exploits a telecommunications system for financial gain by incurring costs on the victim, is known

Submitted by ashley.k· Mar 5, 2026Communication and Network Security

Question

A security engineer is conducting an audit of an organization's Voice over Internet Protocol (VoIP) phone network due to a large increase in charges from their phone provider. The engineer discovers unauthorized endpoints have connected to the phone server from the public internet and placed hundreds of unauthorized calls to parties around the globe. Which type of attack occurred?

Options

  • AControl eavesdropping
  • BToll fraud
  • CCall hijacking
  • DAddress spoofing

How the community answered

(30 responses)
  • A
    13% (4)
  • B
    77% (23)
  • C
    3% (1)
  • D
    7% (2)

Why each option

The scenario describes unauthorized external parties connecting to a VoIP server and placing numerous unauthorized calls globally, resulting in increased charges. This attack, which exploits a telecommunications system for financial gain by incurring costs on the victim, is known as toll fraud.

AControl eavesdropping

Control eavesdropping involves passively listening to the signaling or control information of a VoIP network, not actively making unauthorized calls to generate charges.

BToll fraudCorrect

Toll fraud is an attack where unauthorized individuals gain access to a telecommunications system, such as a Voice over Internet Protocol (VoIP) network, to make calls that incur charges to the legitimate account holder. The question explicitly states 'unauthorized endpoints have connected to the phone server... and placed hundreds of unauthorized calls to parties around the globe' leading to 'a large increase in charges,' which precisely defines the act and consequence of toll fraud.

CCall hijacking

Call hijacking refers to an attacker taking control of an existing, legitimate call between two parties, typically for interception or redirection, rather than initiating new fraudulent calls.

DAddress spoofing

Address spoofing is the act of forging source IP addresses or caller ID information to mask identity or impersonate another entity, but it doesn't describe the broader act of making unauthorized, billable calls.

Concept tested: VoIP attack types, toll fraud

Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/security/dntk/toll_fraud_overview/sec-dntk-toll-fraud-overview.html

Topics

#VoIP security#Toll fraud#Network attacks#Communication security

Community Discussion

No community discussion yet for this question.

Full CISSP Practice