350-801 · Question #423
The security department will audit an IT department to ensure that the proper guidelines are being followed. The reports of the call detail records show unauthorized access to PSTN. Which two…
The correct answer is A. Forced authorization code is used to recognize a dialing extension and authorize an international C. Call forward settings (All/Busy/No Answer) are restricted to internal extensions in the network. To prevent unauthorized PSTN access, administrators should verify the implementation of Forced Authorization Codes for international or sensitive calls and restrict call forwarding options to internal extensions only.
Question
The security department will audit an IT department to ensure that the proper guidelines are being followed. The reports of the call detail records show unauthorized access to PSTN. Which two actions should an administrator check to prevent the unauthorized use of the telephony system? (Choose two.)
Options
- AForced authorization code is used to recognize a dialing extension and authorize an international
- BEnsure that ad hoc conference calls are dropped if an external user is added.
- CCall forward settings (All/Busy/No Answer) are restricted to internal extensions in the network.
- DFor extension mobility, logged-out CSS is restricted to internal extensions and emergencies.
- EAdd an additional firewall between the Cisco UCM server and the Expressway Core server.
How the community answered
(34 responses)- A79% (27)
- B3% (1)
- D12% (4)
- E6% (2)
Why each option
To prevent unauthorized PSTN access, administrators should verify the implementation of Forced Authorization Codes for international or sensitive calls and restrict call forwarding options to internal extensions only.
Forced Authorization Codes (FAC) or Client Matter Codes (CMC) require users to enter a specific code before completing calls to restricted destinations, such as international numbers or premium rate services, thereby preventing unauthorized PSTN access. This ensures that only authorized personnel can dial out to specific costly or sensitive destinations.
Dropping ad hoc conference calls if an external user is added is a security measure related to conferencing, but it does not directly prevent unauthorized PSTN access for regular outbound calls.
Restricting Call Forward All (CFA) settings and other call forwarding options (Busy/No Answer) to internal extensions prevents an attacker or unauthorized user from forwarding calls to external PSTN numbers, which could be exploited for toll fraud or unauthorized outbound calling. This ensures that internal calls stay within the network unless explicitly allowed by other secure mechanisms.
Restricting logged-out CSS for Extension Mobility primarily impacts what services are available when a phone is not logged in, such as preventing unauthenticated internal calls or restricting emergency calls to specific trunks. While a good security practice, it doesn't directly address preventing unauthorized PSTN access via logged-in users or call forwarding.
Adding an additional firewall between UCM and Expressway-C might enhance network segmentation but does not directly address the logical controls within UCM, like FAC or call forwarding restrictions, that prevent unauthorized PSTN use.
Concept tested: Cisco UCM security features for PSTN access control
Source: https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/12_5_1/cucm_b_admin-guide-1251/cucm_b_admin-guide-1251_chapter_010111.html
Topics
Community Discussion
No community discussion yet for this question.