Business Phone Systems Security & Compliance 1 — Questions and Answers
Question 1: Which encryption protocol is specifically designed to secure the audio streams in VoIP calls?
- TLS
- SRTP (Correct answer)
- SSL
- IPsec
Correct answer: SRTP
SRTP (Secure Real-time Transport Protocol) encrypts the actual audio payload of VoIP calls to prevent eavesdropping.
Question 2: What is toll fraud in the context of business phone systems?
- Charging customers hidden fees on invoices
- Unauthorized use of a phone system to make expensive long-distance calls at the business's expense (Correct answer)
- Billing errors caused by misconfigured extensions
- Reselling business phone numbers to third parties
Correct answer: Unauthorized use of a phone system to make expensive long-distance calls at the business's expense
Toll fraud occurs when attackers gain unauthorized access to a business phone system and use it to place expensive calls, leaving the victim with the charges.
Question 3: Which protocol is used to encrypt SIP signaling messages and protect VoIP call setup from interception?
- SRTP
- RTP
- TLS (Correct answer)
- UDP
Correct answer: TLS
TLS (Transport Layer Security) encrypts SIP signaling to protect call setup data such as usernames, phone numbers, and routing information.
Question 4: Under HIPAA, what is required when patient health information (PHI) is communicated over a business phone system?
- All calls must be recorded for audit purposes
- Appropriate safeguards must be in place to protect the confidentiality of PHI (Correct answer)
- Calls must be routed through government-approved servers
- Patients must receive a written transcript of all calls
Correct answer: Appropriate safeguards must be in place to protect the confidentiality of PHI
HIPAA requires covered entities to implement appropriate administrative, physical, and technical safeguards to protect PHI in all forms, including verbal phone communications.
Question 5: What is vishing?
- A type of VoIP hardware malfunction affecting audio clarity
- Voice phishing attacks that use phone calls to trick victims into revealing sensitive information (Correct answer)
- A video conferencing security breach method
- A virtual SIP server hacking technique
Correct answer: Voice phishing attacks that use phone calls to trick victims into revealing sensitive information
Vishing (voice phishing) uses fraudulent phone calls to deceive victims into providing sensitive information such as passwords, account numbers, or Social Security numbers.
Question 6: What is the primary security function of a Session Border Controller (SBC) in a VoIP environment?
- To route calls between multiple offices simultaneously
- To provide security, interoperability, and control at the border of a VoIP network (Correct answer)
- To record all inbound and outbound phone calls
- To convert analog phone signals to digital format
Correct answer: To provide security, interoperability, and control at the border of a VoIP network
An SBC acts as a security and policy enforcement point at the network border, protecting against DoS attacks, unauthorized access, and interoperability issues between different VoIP systems.
Question 7: Which FCC regulation requires businesses to maintain internal Do Not Call lists and honor consumer opt-out requests?
- TCPA (Correct answer)
- HIPAA
- PCI DSS
- GDPR
Correct answer: TCPA
The Telephone Consumer Protection Act (TCPA) requires businesses to maintain Do Not Call lists, honor opt-out requests, and restricts the use of auto-dialers and prerecorded messages.
Which encryption protocol is specifically designed to secure the audio streams in VoIP calls?