nerdexam
Cisco

350-801 · Question #9

As a voice engineer, which two recommendations do you make to your company to optimize Cisco Unified Communications Manager configuration to reduce the number of toll fraud incidents? (Choose two.)

The correct answer is A. Inbounds CSS on any gateway typically should have access to internal destinations only and not E. Classify all route pattern as off-net and prohibit off-net to off-net call transfers in Cisco Unified CM. To mitigate toll fraud, inbound CSS on gateways should be restricted to internal destinations only, and route patterns classified as off-net should prohibit off-net call transfers.

On-Premises Call Control

Question

As a voice engineer, which two recommendations do you make to your company to optimize Cisco Unified Communications Manager configuration to reduce the number of toll fraud incidents? (Choose two.)

Options

  • AInbounds CSS on any gateway typically should have access to internal destinations only and not
  • BClassify all route patterns as on-net and prohibit on-net to on-net call transfers in Cisco Unified
  • CClassify all route patterns as on-net or off-net and prohibit off-net call transfers in Cisco Unified
  • DInbound CSS on any gateway typically should have access to internal destinations and PSTN
  • EClassify all route pattern as off-net and prohibit off-net to off-net call transfers in Cisco Unified CM

How the community answered

(24 responses)
  • A
    71% (17)
  • B
    17% (4)
  • C
    8% (2)
  • D
    4% (1)

Why each option

To mitigate toll fraud, inbound CSS on gateways should be restricted to internal destinations only, and route patterns classified as off-net should prohibit off-net call transfers.

AInbounds CSS on any gateway typically should have access to internal destinations only and notCorrect

Restricting inbound Calling Search Space (CSS) on gateways to internal destinations prevents external attackers from using an inbound gateway to gain access to expensive outbound PSTN routes, which is a common vector for toll fraud. This ensures that calls coming into the system cannot be easily re-routed to external paid numbers.

BClassify all route patterns as on-net and prohibit on-net to on-net call transfers in Cisco Unified

Classifying all route patterns as on-net and prohibiting on-net to on-net transfers would severely restrict legitimate internal call handling and is not a common toll fraud prevention measure.

CClassify all route patterns as on-net or off-net and prohibit off-net call transfers in Cisco Unified

While classifying route patterns as on-net or off-net is a good practice, prohibiting 'off-net call transfers' might be overly restrictive for legitimate business needs, and the key is specifically preventing off-net to off-net transfers for fraud prevention.

DInbound CSS on any gateway typically should have access to internal destinations and PSTN

Allowing inbound CSS on gateways to access internal destinations and PSTN routes would be a major security vulnerability, as it provides a direct path for external callers to access the company's PSTN access for fraudulent calls.

EClassify all route pattern as off-net and prohibit off-net to off-net call transfers in Cisco Unified CMCorrect

Classifying route patterns as off-net and prohibiting off-net to off-net call transfers prevents an attacker from making an inbound call, then transferring it to another external, potentially international, number, thereby exploiting the company's outbound call routes for fraudulent purposes. This closes a critical loophole for call manipulation.

Concept tested: Toll fraud prevention in CUCM

Source: https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/srnd/collab12/collab12/security.html

Topics

#Toll Fraud Prevention#CUCM Security#Calling Search Space#Call Transfer Control

Community Discussion

No community discussion yet for this question.

Full 350-801 Practice