350-801 · Question #9
As a voice engineer, which two recommendations do you make to your company to optimize Cisco Unified Communications Manager configuration to reduce the number of toll fraud incidents? (Choose two.)
The correct answer is A. Inbounds CSS on any gateway typically should have access to internal destinations only and not E. Classify all route pattern as off-net and prohibit off-net to off-net call transfers in Cisco Unified CM. To mitigate toll fraud, inbound CSS on gateways should be restricted to internal destinations only, and route patterns classified as off-net should prohibit off-net call transfers.
Question
As a voice engineer, which two recommendations do you make to your company to optimize Cisco Unified Communications Manager configuration to reduce the number of toll fraud incidents? (Choose two.)
Options
- AInbounds CSS on any gateway typically should have access to internal destinations only and not
- BClassify all route patterns as on-net and prohibit on-net to on-net call transfers in Cisco Unified
- CClassify all route patterns as on-net or off-net and prohibit off-net call transfers in Cisco Unified
- DInbound CSS on any gateway typically should have access to internal destinations and PSTN
- EClassify all route pattern as off-net and prohibit off-net to off-net call transfers in Cisco Unified CM
How the community answered
(24 responses)- A71% (17)
- B17% (4)
- C8% (2)
- D4% (1)
Why each option
To mitigate toll fraud, inbound CSS on gateways should be restricted to internal destinations only, and route patterns classified as off-net should prohibit off-net call transfers.
Restricting inbound Calling Search Space (CSS) on gateways to internal destinations prevents external attackers from using an inbound gateway to gain access to expensive outbound PSTN routes, which is a common vector for toll fraud. This ensures that calls coming into the system cannot be easily re-routed to external paid numbers.
Classifying all route patterns as on-net and prohibiting on-net to on-net transfers would severely restrict legitimate internal call handling and is not a common toll fraud prevention measure.
While classifying route patterns as on-net or off-net is a good practice, prohibiting 'off-net call transfers' might be overly restrictive for legitimate business needs, and the key is specifically preventing off-net to off-net transfers for fraud prevention.
Allowing inbound CSS on gateways to access internal destinations and PSTN routes would be a major security vulnerability, as it provides a direct path for external callers to access the company's PSTN access for fraudulent calls.
Classifying route patterns as off-net and prohibiting off-net to off-net call transfers prevents an attacker from making an inbound call, then transferring it to another external, potentially international, number, thereby exploiting the company's outbound call routes for fraudulent purposes. This closes a critical loophole for call manipulation.
Concept tested: Toll fraud prevention in CUCM
Source: https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/srnd/collab12/collab12/security.html
Topics
Community Discussion
No community discussion yet for this question.