← All Business Phone Systems Flashcard Decks

Security & Compliance Flashcards

7 cards from real Business Phone Systems practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Security & Compliance flashcards as text
  1. What is the recommended best practice for securing administrator access to a business VoIP phone system?

    Answer: Enabling multi-factor authentication combined with a strong password policy

    Multi-factor authentication plus strong passwords significantly reduces the risk of unauthorized administrative access, which is especially critical for VoIP systems that can be used for toll fraud.

  2. Under GDPR, what must a business do before recording a call with a European customer?

    Answer: Inform the customer about the recording and obtain their consent where required

    GDPR requires transparency about data processing activities, including call recording, and often requires explicit consent since call recordings contain personal data.

  3. How are Call Detail Records (CDRs) used for security monitoring on business phone systems?

    Answer: They log call metadata to help detect anomalous patterns that may indicate fraud or unauthorized access

    CDRs capture metadata (caller, recipient, time, duration, cost) for every call, allowing administrators to identify unusual spikes or patterns that may signal toll fraud or a compromised account.

  4. Which combination of protocols provides the most complete protection against eavesdropping on VoIP calls?

    Answer: TLS for SIP signaling combined with SRTP for media encryption

    TLS encrypts the SIP signaling that sets up the call, while SRTP encrypts the actual voice media, together providing end-to-end protection against eavesdropping.

  5. Which social engineering attack commonly targets business phone systems to gain unauthorized access?

    Answer: Pretexting, where attackers impersonate IT support staff to manipulate employees into revealing credentials

    Pretexting involves an attacker fabricating a convincing scenario — such as posing as IT support — to trick employees into providing login credentials or making unauthorized system changes.

  6. How does IP reputation filtering improve the security of a business VoIP system?

    Answer: It blocks incoming traffic from IP addresses known to be associated with malicious activity

    IP reputation filtering compares incoming connection attempts against threat intelligence databases and blocks known malicious IP addresses before they can interact with the phone system.

  7. What is the recommended practice for managing firmware updates on business VoIP phones and systems?

    Answer: Apply security patches and firmware updates on a regular schedule to address known vulnerabilities

    Regular firmware updates patch known security vulnerabilities in VoIP endpoints and servers; unpatched devices are a common entry point for toll fraud and unauthorized access.

Security & Compliance Flashcards — Business Phone Systems Study Cards with Answers