How to Prevent Unauthorized PSTN Access in Cisco UCM?

The security department will audit an IT department to ensure that the proper guidelines are being followed. The reports of the call detail records show unauthorized access to PSTN. Which two actions should an administrator check to prevent the unauthorized use of the telephony system? (Choose two.)

  1. Forced authorization code is used to recognize a dialing extension and authorize an international call.
  2. Ensure that ad hoc conference calls are dropped if an external user is added.
  3. Call forward settings (All/Busy/No Answer) are restricted to internal extensions in the network. Source Reference Answer
  4. For extension mobility, logged-out CSS is restricted to internal extensions and emergencies. Source Reference Answer
  5. Add an additional firewall between the Cisco UCM server and the Expressway Core server.

Community Votes

CD
100%

100% of anonymous learners picked answer CD. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests knowledge of UCM security best practices for controlling outbound telephony access, where candidates often confuse feature-specific restrictions like Forced Authorization Codes with partition-based CSS controls.

Securing Cisco Unified Communications Manager requires restricting call forwarding and extension mobility configurations to internal partitions to block external PSTN toll fraud. Community consensus strongly validates this approach as the most effective method to mitigate unauthorized telephony usage.

Option A is frequently selected incorrectly because administrators mistakenly believe Forced Authorization Codes automatically validate extensions for premium routes, whereas FAC actually requires manual numeric code entry rather than recognizing the dialed extension itself.

Community Discussion (5 comments)

cyberknock 👍 2 Selected: CD
A is not right, FAC does not recognize an extension, it asks for a code to enter
WilliamC 👍 2
Provide segmentation and control to the number that can be called, or vice versa. As a leading practice recommendation, either disable Call Forward All or limit it to an extension within your Collaboration network. Call Forward Busy and Call Forward No Answer should also be limited to internal partitions only. For phones with extension mobility, a logged-out CSS should be restricted to internal and emergency partitions only. https://www.ciscopress.com/articles/article.asp?p=2218297&seqNum=10
WilliamC 👍 2 Selected: CD
To prevent
e971987 👍 1
AC are right!!
84db7a1 👍 1
AC are correct

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Restricting call forward settings to internal partitions prevents attackers or malicious insiders from hijacking lines to route calls externally through the PSTN. Similarly, configuring a restricted logged-out Calling Search Space for Extension Mobility ensures that devices revert to safe internal routing when unassigned, blocking unauthorized long-distance dialing. These controls directly address the call detail record findings by enforcing least-privilege dialing permissions at the device and line level.

Why the Other Options Are Wrong

Option A misinterprets how Forced Authorization Codes function, as they require manual code entry rather than automatically validating extensions for premium routes. Option B addresses ad hoc conferencing limits, which do not directly control individual PSTN dialing permissions or prevent toll fraud on standard lines. Option E suggests adding another firewall between UCM and Expressway Core, which enhances signaling security but does not restrict internal telephony routing policies or resolve PSTN access misuse within the collaboration network.

Community Comment Notes

Candidates consistently validate options C and D based on industry best practices for collaboration security. As noted in the discussion, limiting call forwarding to internal extensions is a leading practice recommendation to avoid external number exposure. Another contributor correctly clarifies that FAC prompts for a code instead of recognizing extensions, steering test-takers away from option A. The unanimous vote distribution reflects strong alignment with official Cisco hardening guidelines.

Official Reference

Exam Strategy

When troubleshooting PSTN security gaps in exam scenarios, always prioritize partition-based CSS restrictions over authentication mechanisms like FAC or PINs. Focus on how device states and forwarding behaviors interact with calling privileges to identify the most direct mitigation steps.

Related Analysis

← Back to 350-801 Study Guide