How to Prevent Unauthorized PSTN Access in Cisco UCM?
The security department will audit an IT department to ensure that the proper guidelines are being followed. The reports of the call detail records show unauthorized access to PSTN. Which two actions should an administrator check to prevent the unauthorized use of the telephony system? (Choose two.)
Community Votes
100% of anonymous learners picked answer CD. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests knowledge of UCM security best practices for controlling outbound telephony access, where candidates often confuse feature-specific restrictions like Forced Authorization Codes with partition-based CSS controls.
Securing Cisco Unified Communications Manager requires restricting call forwarding and extension mobility configurations to internal partitions to block external PSTN toll fraud. Community consensus strongly validates this approach as the most effective method to mitigate unauthorized telephony usage.
Option A is frequently selected incorrectly because administrators mistakenly believe Forced Authorization Codes automatically validate extensions for premium routes, whereas FAC actually requires manual numeric code entry rather than recognizing the dialed extension itself.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Restricting call forward settings to internal partitions prevents attackers or malicious insiders from hijacking lines to route calls externally through the PSTN. Similarly, configuring a restricted logged-out Calling Search Space for Extension Mobility ensures that devices revert to safe internal routing when unassigned, blocking unauthorized long-distance dialing. These controls directly address the call detail record findings by enforcing least-privilege dialing permissions at the device and line level.Why the Other Options Are Wrong
Option A misinterprets how Forced Authorization Codes function, as they require manual code entry rather than automatically validating extensions for premium routes. Option B addresses ad hoc conferencing limits, which do not directly control individual PSTN dialing permissions or prevent toll fraud on standard lines. Option E suggests adding another firewall between UCM and Expressway Core, which enhances signaling security but does not restrict internal telephony routing policies or resolve PSTN access misuse within the collaboration network.Community Comment Notes
Candidates consistently validate options C and D based on industry best practices for collaboration security. As noted in the discussion, limiting call forwarding to internal extensions is a leading practice recommendation to avoid external number exposure. Another contributor correctly clarifies that FAC prompts for a code instead of recognizing extensions, steering test-takers away from option A. The unanimous vote distribution reflects strong alignment with official Cisco hardening guidelines.Official Reference
- https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/14_0/ucsbk/cucsbk_chapter_010.html
- https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/security/14_0/ucssb/ucssb_chapter_010.html
- https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-ip-phone-8800-series/214837/securing-collaboration-best-practices.html
Exam Strategy
When troubleshooting PSTN security gaps in exam scenarios, always prioritize partition-based CSS restrictions over authentication mechanisms like FAC or PINs. Focus on how device states and forwarding behaviors interact with calling privileges to identify the most direct mitigation steps.