nerdexam
(ISC)2

SSCP · Question #757

Which of the following countermeasures would be the most appropriate to prevent possible intrusion or damage from wardialing attacks?

The correct answer is B. Require user authentication. Knowlege of modem numbers is a poor access control method as an attacker can discover modem numbers by dialing all numbers in a range. Requiring user authentication before remote access is granted will help in avoiding unauthorized access over a modem line. "Monitoring and…

Submitted by carlos_mx· Apr 18, 2026Access Controls

Question

Which of the following countermeasures would be the most appropriate to prevent possible intrusion or damage from wardialing attacks?

Options

  • AMonitoring and auditing for such activity
  • BRequire user authentication
  • CMaking sure only necessary phone numbers are made public
  • DUsing completely different numbers for voice and data accesses

How the community answered

(31 responses)
  • A
    3% (1)
  • B
    87% (27)
  • C
    3% (1)
  • D
    6% (2)

Explanation

Knowlege of modem numbers is a poor access control method as an attacker can discover modem numbers by dialing all numbers in a range. Requiring user authentication before remote access is granted will help in avoiding unauthorized access over a modem line. "Monitoring and auditing for such activity" is incorrect. While monitoring and auditing can assist in detecting a wardialing attack, they do not defend against a successful wardialing attack. "Making sure that only necessary phone numbers are made public" is incorrect. Since a wardialing attack blindly calls all numbers in a range, whether certain numbers in the range are public or not is irrelevant. "Using completely different numbers for voice and data accesses" is incorrect. Using different number ranges for voice and data access might help prevent an attacker from stumbling across the data lines while wardialing the public voice number range but this is not an adequate

Topics

#Wardialing#Authentication#Access Control#Remote Access Security

Community Discussion

No community discussion yet for this question.

Full SSCP Practice