nerdexam
GIAC

GCIA · Question #8

John works as a Network Security Administrator for NetPerfect Inc. The manager of the company has told John that the company's phone bill has increased drastically. John suspects that the company's…

The correct answer is C. Phreaking. Phreaking is the term for hacking or exploiting telephone systems, making it the correct attack type when a company's phone system has been compromised to run up unauthorized charges.

Advanced Incident Response & Digital Forensics Fundamentals

Question

John works as a Network Security Administrator for NetPerfect Inc. The manager of the company has told John that the company's phone bill has increased drastically. John suspects that the company's phone system has been cracked by a malicious hacker. Which attack is used by malicious hackers to crack the phone system?

Options

  • AWar dialing
  • BSequence++ attack
  • CPhreaking
  • DMan-in-the-middle attack

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    12% (3)
  • C
    80% (20)
  • D
    4% (1)

Why each option

Phreaking is the term for hacking or exploiting telephone systems, making it the correct attack type when a company's phone system has been compromised to run up unauthorized charges.

AWar dialing

War dialing is a technique of automatically scanning telephone numbers to identify modems or fax machines and is used for reconnaissance, not for directly exploiting or billing against a company's phone system.

BSequence++ attack

Sequence++ attack is not a recognized standard attack category and has no established definition related to telephone system exploitation.

CPhreakingCorrect

Phreaking refers to the practice of exploiting telephone networks and PBX systems to make unauthorized calls, manipulate billing, or gain control over telephony infrastructure. It is the classic attack used by malicious hackers to crack phone systems, which directly explains the drastic increase in the company's phone bill caused by unauthorized usage of its telephony resources.

DMan-in-the-middle attack

A man-in-the-middle attack intercepts communications between two parties over a network and is not specifically associated with compromising telephone billing systems or PBX infrastructure.

Concept tested: Telephone system exploitation via phreaking

Source: https://www.comptia.org/content/guides/what-is-phreaking

Topics

#phreaking#telecommunications attack#phone system#social engineering

Community Discussion

No community discussion yet for this question.

Full GCIA Practice