Security & Compliance Flashcards
7 cards from real Business Phone Systems practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Security & Compliance flashcards as text
What does PCI DSS require when processing credit card payments over the phone?
Answer: Cardholder data must be protected and agents must never store CVV codes after authorization
PCI DSS prohibits storing CVV codes post-authorization and requires phone-based payment environments to implement controls that protect cardholder data throughout the transaction.
How do malicious actors use SIP scanning against business phone systems?
Answer: To discover and exploit vulnerable VoIP devices or servers for toll fraud or eavesdropping
SIP scanning is a reconnaissance technique where attackers probe networks for exposed VoIP devices with weak credentials or known vulnerabilities that can be exploited.
Under US state wiretapping laws, when must businesses inform callers that their call is being recorded?
Answer: When required by applicable state law, since some states require all-party consent
Recording disclosure requirements vary by state — two-party (all-party) consent states require informing all participants, so businesses must follow the stricter applicable law.
What is the STIR/SHAKEN framework designed to address in the telecom industry?
Answer: Caller ID spoofing and fraudulent robocalls
STIR/SHAKEN is a caller authentication framework mandated by the FCC that verifies the caller's identity matches the number displayed, helping combat spoofed robocalls.
Which type of denial-of-service attack specifically targets VoIP infrastructure?
Answer: SIP INVITE flood attack
A SIP INVITE flood overwhelms a VoIP server with massive numbers of call initiation requests, exhausting resources and disrupting legitimate call processing.
Which security measure helps ensure only authorized devices can register on a business VoIP phone system?
Answer: MAC address filtering or SIP digest authentication for device registration
MAC address filtering or SIP digest authentication verifies device identity before allowing registration, preventing unauthorized phones from connecting to the phone system.
What does E-911 compliance require of business VoIP phone systems?
Answer: The system must transmit accurate physical location data with every emergency call
E-911 compliance requires that when any user dials 911, the phone system automatically provides emergency services with the caller's accurate physical location.