Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 151 discussion

Actual exam question from ISC's CISSP
Question #: 151
Topic #: 1
[All CISSP Questions]

When designing a new Voice over Internet Protocol (VoIP) network, an organization's top concern is preventing unauthorized users accessing the VoIP network.
Which of the following will BEST help secure the VoIP network?

  • A. 802.11g
  • B. Web application firewall (WAF)
  • C. Transport Layer Security (TLS)
  • D. 802.1x
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Bhuraw
Highly Voted 2 years ago
Selected Answer: D
Where does Examtopics get their answers from?
upvoted 16 times
MShaaban
1 year, 3 months ago
Hahaha, I was thinking the same 😂. Agree D is the answer.
upvoted 4 times
...
Jamati
2 years ago
I never look at their answers, I just go straight to the discussion.
upvoted 4 times
...
jackdryan
1 year, 6 months ago
D is correct
upvoted 2 times
...
...
Qwertyloopback
Highly Voted 1 year, 8 months ago
Selected Answer: C
I am going with C on this one. Here is my reasoning from research: The CISSP 9ed mentions 802.1x but as a vulnerability, not as a protection. It basically states that due to the nature of voip devices, it is easy to spoof Mac addresses and get past layered defenses. It also mentions TLS and SRTP as protection mechanisms. Cisco has an article that I found helpful. (Link below) It does not mention 802.1x at all but does go into to TLS and SRTP. https://www.cisco.com/c/en/us/solutions/small-business/resource-center/security/tips-ip-phone-security.html#~configure-and-protect-systems Given that SRTP is not an option. TLS seems to be the best answer in this case.
upvoted 9 times
...
KJ44
Most Recent 2 weeks, 5 days ago
Selected Answer: D
802.1x authenticates the users before allowing access. TLS and other protocols will secure the call while in progress. The questions asks how to prevent unauthorized users, so the answer is 802.1x
upvoted 1 times
...
Treebeard88
1 month ago
Selected Answer: C
802.1X is a network authentication and access control mechanism, while TLS is a protocol that protects data transfers between a client and a web server
upvoted 1 times
...
8b48948
7 months ago
Has to be C - 802.1x is port authentication.
upvoted 1 times
...
dm808
7 months, 4 weeks ago
Selected Answer: D
I think the VOIP detail is irrelevant. TLS will provide privacy between sessions. The question is asking about preventing unauthorized access to the network.. so it has to be D
upvoted 1 times
...
homeysl
8 months, 1 week ago
Selected Answer: D
Question is asking about preventing access.
upvoted 1 times
...
splash2357
10 months ago
Going with D. TLS protect man-in-the-middle attackers who is already in range within the VOIP network from eavesdropping connections. It provide no authentication nor authorization that prevent unauthorized users getting in the network. With TLS, attackers in range may still connect their devices to the VOIP network and make connections (just that they can't eavesdrop others).
upvoted 2 times
...
YesPlease
11 months, 2 weeks ago
Answer C) Transport Layer Security (TLS) I really hate these ambiguous questions. Essentially, 802.11g and 802.1x are the same...they provide a protocol to authenticate network traffic...just one happens to be direct and state it is for wireless. If two options are the same, then it must mean that they are not the right choice and it is must be TLS. ( At least one would think)
upvoted 1 times
splash2357
10 months ago
No, 802.11g is a standard for Wi-Fi (a legacy one though) https://www.intel.com/content/www/us/en/support/articles/000005725/wireless/legacy-intel-wireless-products.html
upvoted 1 times
...
...
isaac592
1 year, 1 month ago
Selected Answer: C
Similar to @qwertyloopback, went with C because SRTP was not an option but you can encrypt VoIP SIP traffic with TLS.
upvoted 1 times
...
homeysl
1 year, 1 month ago
Selected Answer: C
I did not see SRTP, so it must be TLS.
upvoted 2 times
...
74gjd_37
1 year, 2 months ago
Selected Answer: D
https://www.juniper.net/documentation/us/en/software/junos/user-access/topics/concept/802-1x-pnac-voip-understanding-mx-series.html When you use Voice over IP (VoIP), you can connect IP telephones to the router and configure IEEE 802.1X authentication for 802.1X-compatible IP telephones. Starting with Junos OS Release 14.2, 802.1X authentication provides network edge security, protecting Ethernet LANs from unauthorized user access. When VoIP is used with 802.1X, the RADIUS server authenticates the phone. You can configure 802.1X authentication to work with VoIP in multiple supplicant or single supplicant mode. In multiple-supplicant mode, the 802.1X process allows multiple supplicants to connect to the interface. The BEST option to secure the VoIP network is option D, 802.1x. This is a standard for port-based network access control that provides authentication and authorization to devices trying to connect to the network. By implementing 802.1x, only authorized devices can connect to the VoIP network, preventing unauthorized access.
upvoted 2 times
...
BoZT
1 year, 2 months ago
Selected Answer: C
Bard says TLS is a cryptographic protocol that encrypts data in transit between two endpoints. This means that even if an unauthorized user is able to intercept the data, they will not be able to read it. TLS is the most widely used encryption protocol for VoIP traffic, and it is considered to be very secure. The other options are not as secure as TLS. 802.11g is a wireless networking standard that does not provide any encryption by default. A WAF is a firewall that is designed to protect web applications from attacks. It can be used to block malicious traffic, but it does not encrypt data. 802.1x is a network access control protocol that can be used to authenticate users before they are allowed to access the network. However, it does not encrypt data in transit. In conclusion, TLS is the best way to secure a VoIP network from unauthorized access.
upvoted 5 times
...
Bach1968
1 year, 4 months ago
Selected Answer: D
The BEST option to help secure a Voice over Internet Protocol (VoIP) network and prevent unauthorized access is option D, 802.1x. 802.1x is a network access control protocol that provides authentication and authorization for devices attempting to connect to a network. It allows for user-based authentication and provides a secure method to control access to the VoIP network. By implementing 802.1x, only authorized users or devices with valid credentials will be granted access to the network, while unauthorized users will be prevented from connecting.
upvoted 1 times
...
HughJassole
1 year, 5 months ago
C. "Call encryption uses Transport Layer Security (TLS) and Secure Real-time Transport Protocol (SRTP). These VoIP protocols work together to establish high-grade security in every call." "For the greatest interoperability, SIP isn’t encrypted." https://www.nextiva.com/blog/voip-security.html
upvoted 2 times
...
dmo_d
1 year, 6 months ago
Selected Answer: C
see my previous comment :-)
upvoted 1 times
...
dmo_d
1 year, 6 months ago
Answer D is not the best one because 802.1x only provides protection on the network level - regardless of the services. But in this scenario the "voip network" shall be protected. This can be achieved using TLS. With TLS other entities in the network cannot get unencrypted VOIP traffic. Furthermore TLS provides (optional) mutual authentication (mTLS). So only legitimate VoIP endpoints can "access" the mTLS protected "VoIP network".
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...