CISSP · Question #879
A security engineer is conducting an audit of an organization's Voice over Internet Protocol (VoIP) phone network due to a large increase in charges from their phone provider. The engineer discovers u
The correct answer is B. Toll fraud. The scenario describes unauthorized external parties connecting to a VoIP server and placing numerous unauthorized calls globally, resulting in increased charges. This attack, which exploits a telecommunications system for financial gain by incurring costs on the victim, is known
Question
A security engineer is conducting an audit of an organization's Voice over Internet Protocol (VoIP) phone network due to a large increase in charges from their phone provider. The engineer discovers unauthorized endpoints have connected to the phone server from the public internet and placed hundreds of unauthorized calls to parties around the globe. Which type of attack occurred?
Options
- AControl eavesdropping
- BToll fraud
- CCall hijacking
- DAddress spoofing
How the community answered
(30 responses)- A13% (4)
- B77% (23)
- C3% (1)
- D7% (2)
Why each option
The scenario describes unauthorized external parties connecting to a VoIP server and placing numerous unauthorized calls globally, resulting in increased charges. This attack, which exploits a telecommunications system for financial gain by incurring costs on the victim, is known as toll fraud.
Control eavesdropping involves passively listening to the signaling or control information of a VoIP network, not actively making unauthorized calls to generate charges.
Toll fraud is an attack where unauthorized individuals gain access to a telecommunications system, such as a Voice over Internet Protocol (VoIP) network, to make calls that incur charges to the legitimate account holder. The question explicitly states 'unauthorized endpoints have connected to the phone server... and placed hundreds of unauthorized calls to parties around the globe' leading to 'a large increase in charges,' which precisely defines the act and consequence of toll fraud.
Call hijacking refers to an attacker taking control of an existing, legitimate call between two parties, typically for interception or redirection, rather than initiating new fraudulent calls.
Address spoofing is the act of forging source IP addresses or caller ID information to mask identity or impersonate another entity, but it doesn't describe the broader act of making unauthorized, billable calls.
Concept tested: VoIP attack types, toll fraud
Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/security/dntk/toll_fraud_overview/sec-dntk-toll-fraud-overview.html
Topics
Community Discussion
No community discussion yet for this question.