Buy Latest Feb 18, 2024 300-820 Exam Q&A PDF - One Year Free Update
Download the Latest 300-820 Dump - 2024 300-820 Exam Questions
Mobile & Remote Access – 25%
To deal with the questions from this domain, the examinees need to prove that they are proficient in:
- Configuring a Mobile & Remote Access solution (including DNS records types; certificates, HTTP allow list; Unified Communications traversal zones; Unified Communications configuration within Expressway; SIP trunk security profile within Cisco Unified Communications Manager);
- Troubleshooting a Mobile & Remote Access solution.
NEW QUESTION # 61
Which zone is required between Expressway-E and Expressway-C in Mobile and Remote Access deployments?
- A. Unified Communications traversal zone
- B. neighbor zone
- C. DNS zone
- D. traversal zone
Answer: A
NEW QUESTION # 62
Refer to the exhibit.
While troubleshooting Cisco Jabber login issues, there are some error messages. Why is the Jabber client unable to sign in?
- A. incorrect login credentials
- B. XMPP bind failures
- C. service discovery issues
- D. down Cisco Unified Communications Manager server
Answer: B
NEW QUESTION # 63
During the deployment of a Cisco Webex Video Mesh, where do on-premises SIP endpoints send signaling?
- A. to the switching services
- B. On-premises endpoints cannot participate in Cisco Webex Video Mesh
- C. to the call control environment (Unified CM or Expressway)
- D. to the cloud
Answer: C
NEW QUESTION # 64
What is the purpose of a transform in the Expressway server?
- A. A transform changes the audio codec when the call goes through the Expressway.
- B. A transform changes an alias that matches certain criteria into another alias.
- C. A transform has the function as a neighbor zone in the Expressway. It creates a connection with another server.
- D. A transform is used to route calls to a destination.
Answer: B
NEW QUESTION # 65
D18912E1457D5D1DDCBD40AB3BF70D5D
Refer to the exhibit showing logs from the Expressway-C, a copy of the Expressway-E certificate, and the UC traversal zone configuration for the Expressway-C. An office administrator is deploying mobile and remote access and sees an issue with the UC traversal zone. The zone is showing "TLS negotiation failure". What is causing this issue?
- A. The Expressway-E certificate includes the Expressway-C FQDN as a SAN entry
- B. The Expressway-C is missing the FQDN of Cisco UCM in the Common Name of its certificate
- C. The Expressway-E does not have the FQDN of Cisco UCM listed as a SAN in its certificate
- D. In the UC Traversal Zone on the Expressway-C, the peer address is set to the IP of the Expressway-E, which is not a SAN entry in the Expressway-E certificate
Answer: C
NEW QUESTION # 66
Which two statements about Mobile and Remote Access certificate are true? (Choose two.)
- A. Expressway must generate certificate signing request.
- B. You must upload the root certificates in the phone trust store.
- C. The Jabber client can work with public or private CA signed certificate.
- D. Expressway Core can use private CA signed certificate.
- E. Expressway Edge must use public CA signed certificate.
Answer: D,E
Explanation:
Public vs. Private Certificate Authority (CA)
There are a number of options to sign certificates on the Expressway-C and E servers. You can opt to have the Certificate Signing Request (CSR) signed by a public CA such as GoDaddy, Verisign, or others, or you can sign it internally using your own Certificate Authority (CA) (can either be self signed using openSSL or an internal enterprise CA such as a Microsoft Windows server).
The only server that is really required to be signed by a public CA is the Expressway-E. This is the only server that clients will see the certificate from when singing in via MRA therefore using a public CA will ensure that users do not have to manually accept the certificate. Using an internal CA to sign the Expressway-E will work but first time users will be prompted to accept the untrusted certificate. MRA registration of 7800 and 8800 series phones also will not work with internal certificates because their certificate trust list cannot be modified. For simplicity it is suggested that your Expressway-C and Expressway-E certificates both be signed by the same CA however this is not a requirement as long as you properly configured the trusted CA lists on both servers.
https://www.cisco.com/c/en/us/support/docs/unified-communications/expressway/213872- configure-and-troubleshoot-collaboration.html
NEW QUESTION # 67
Which zone is required on a B2B deployment between Expressway-C and Expressway-E?
- A. neighbor zone
- B. DNS zone
- C. default zone
- D. traversal zone
Answer: D
NEW QUESTION # 68
Refer to the exhibit.
While troubleshooting Cisco Jabber login issues, there are some error messages. Why is the Jabber client unable to sign in?
- A. incorrect login credentials
- B. XMPP bind failures
- C. service discovery issues
- D. down Cisco Unified Communications Manager server
Answer: B
Explanation:
Explanation
https://www.cisco.com/c/dam/en/us/td/docs/voice_ip_comm/expressway/config_guide/X8-5/Mobile-Remote-Ac
NEW QUESTION # 69 
Refer to the exhibit. An engineer is deploying mobile and remote access in an environment that already had functioning Business to Business calling. Mobile and remote access SIP registrations are failing. To troubleshoot, SIP logs were collected. How is this issue resolved?
- A. Change the "Incoming Port" in the SIP Trunk Security Profile for the Expressway-C to not match SIP line registrations
- B. Change the SIP profile on the SIP trunk for the Expressway-E to Standard SIP Profile for TelePresence Endpoint
- C. Write a custom normalization script since the "vcs-interop" normalization script does not allow registrations
- D. Enable autoregistration for the appropriate DN range on the Cisco UCM servers running the CallManager service
Answer: A
NEW QUESTION # 70
Cisco Collaboration endpoints are exchanging encrypted signaling messages.
What is one major complication in implementing NAT ALG for voice and video devices?
- A. The NAT ALG cannot inspect the contents of encrypted signaling messages.
- B. Source addresses cannot provide the destination addresses that remote endpoints should use for return packets.
- C. NAT ALG introduces jitter in the voice path.
- D. Internal endpoints cannot use addresses from the private address space.
Answer: A
Explanation:
Explanation
https://www.voipinfo.net/docs/cisco/collab11.pdf
NEW QUESTION # 71
Refer to the exhibit.
Which description of the transformation is true?
- A. It converts [email protected]:<port> to [email protected]
- B. It changes all patterns that begin with [email protected]:<port> to [email protected]
- C. It changes [email protected]:<port> to [email protected]
- D. It converts [email protected]:<port> to [email protected]
Answer: D
NEW QUESTION # 72
Refer to the exhibit.
Mobile Cisco Jabber cannot register with on-premises Cisco Unified Communications Manager using Mobile and Remote Access. Some logs were captured on Expressway Edge.
Which action corrects this problem?
- A. Ensure that the _cisco-uds SRV record has been configured.
- B. Ensure that the peer address does not match the Common Name on certificate.
- C. Ensure that the credential has been entered correctly.
- D. Ensure that the SIP domains are added on Expressway Core.
Answer: C
NEW QUESTION # 73
Cisco Expressways are being deployed for Mobile and Remote Access. The Expressway-E internal interface (LAN1) IP is 192.168.100.10/24, and the external interface (LAN2) IP is
172.16.100.10/24.
The Expressway-C IP is 192.168.20.10/24. The default gateway for each subnet is the first useable address. How must the Expressway-E be configured to allow proper routing to the internal and external networks?
- A. IPv4 gateway: 192.168.100.1, and a static route for the 172.16.100.0/24 subnet using LAN2
- B. IPv4 gateway: 192.168.100.1, and a static route for the 192.168.20.0/24 subnet using LAN1
- C. IPv4 gateway: 172.16.100.1, and a static route for the 192.168.20.0/24 subnet using LAN1
- D. IPv4 gateway: 172.16.100.1, and a static route for the 192.168.100.0/24 subnet using LAN1
Answer: C
NEW QUESTION # 74
Refer to the exhibit.
When a Jabber user attempts to connect from outside of the organization, the user enters the login information as "[email protected]" and receives the error "Cannot find your services Automatically". The engineer tries to resolve SRV records used by Jabber.
DNS A record "expressway-e.example.com" points to the Expressway-E IP and "cucm.example.com" points to the Cisco Unified Communications Manager.
Which change resolves the DNS problem?
- A. Change cisco-uds to point to the Expressway-E FQDN.
- B. Change the priority of the SRV record for cisco-uds.
- C. Change the collab-edge record to point to 5061.
- D. Remove the cisco-uds SRV record for the external DNS.
Answer: D
NEW QUESTION # 75
Jabber cannot log in via Mobile and Remote Access. You inspect Expressway-C logs and see this error message:
XCP_JABBERD Detail="Unable to connect to host '%IP%', port 7400:(111) Connection refused" Which is the cause of this issue?
- A. The destination port for Expressway-E is set to 7400 instead of 8443 on the Expressway-C.
- B. The XCP Service is not activated on Expressway-E.
- C. Expressway-E is listening on the wrong IP interface.
- D. Rich Media Session licenses are not activated on Expressway-E.
Answer: C
Explanation:
Explanation
https://www.cisco.com/c/en/us/support/docs/unified-communications/expressway/118798-technote-cucm-00.htm
NEW QUESTION # 76
An engineer must configure Mobile and Remote Access. One of the requirements is to expect Cisco Jabber users to enter [email protected] as the login userid. Which DNS record must the engineer modify to start implementing this requirement?
- A. _cisco-uds._tls.cisco.com
- B. _cisco-uds._tcp.cisco.com
- C. _collab-edge._tls.cisco.com
- D. _cuplogin._tcp.cisco.com
Answer: C
NEW QUESTION # 77
Which commands disable SIP Inspection on the Cisco ASA FirePOWER firewall?
- A. hostname(config)#policy-map global_policy
hostname(config-pmap)#class-map inspection default
hostname(config-pmap)#no inspect_sip - B. hostname(config)#policy-map global_policy
hostname(config-pmap)#class-map inspection_default
hostname(config-pmap)#no inspect sip - C. hostname#no inspect sip
- D. hostname(config)#no inspect_sip
Answer: B
NEW QUESTION # 78
When the network requirements are configured for a new Video Mesh deployment, which firewall ports are required so that Video Mesh cascade signaling succeeds?
- A. UDP 33432 through 33433
- B. UDP 5004 and 5005
- C. TCP 443 and 8443
- D. TCP 443 and 444
Answer: D
NEW QUESTION # 79
Which mode should be used when Call Policy is configured on Expressways?
- A. extended CPL
- B. local CPL, policy service, and off
- C. remote CPL
- D. on
Answer: D
Explanation:
Explanation
https://www.cisco.com/c/dam/en/us/td/docs/voice_ip_comm/expressway/admin_guide/Cisco-Expressway-Admin
NEW QUESTION # 80 
Refer to the exhibit. An ISDN gateway is registered to Expressway-C with a prefix of 9 and/or it has a neighbor zone specified that routes calls starting with a 9.
Which value should be entered into the "Source" field to prevent toll fraud regardless at origin of the call?
- A. Any
- B. All
- C. Neighbor Zone
- D. Traversal Zone
Answer: B
NEW QUESTION # 81
An engineer configures a Cisco Collaboration environment to use Mobile and Remote Access for external access for company users. The engineer uses OAuth with refresh on the Cisco UCM SIP lines for extra security and improved user experience. During the setup, Mobile and Remote Access does not work, it is enabled on the Cisco UCM and Cisco Expressways. SIP trunks on ports 5090 and 5091 are configured to avoid conflicts with other SIP trunks between internal Cisco UCM clusters. The traversal zone also uses port 6500. The traversal zone between Expressways shows no errors, and the requests hit Expressway-E from the Internet. What is the reason that the solution does not work?
- A. The default port for Mobile and Remote Access is 6001. Therefore, the traversal port must be port
6001 for Mobile and Remote Access to work. - B. The default port for Mobile and Remote Access is 5091, which creates a conflict with the existing SIP trunks.
- C. Mobile and Remote Access does not support OAuth with refresh with this configuration,
- D. The default port for Mobile and Remote Access is 6500, which creates a conflict with the existing traversal zone port.
Answer: B
NEW QUESTION # 82
Which dial plan component is configured in Expressway-C to route a call to the Cisco UCM?
- A. call policy
- B. call routing
- C. traversal subzone
- D. search rule
Answer: D
Explanation:
Search rules specify the range of telephone numbers / URIs to be handled by this neighbor Unified CM. They can also be used to transform URIs before they are sent to the neighbor.
https://www.cisco.com/c/dam/en/us/td/docs/voice_ip_comm/expressway/config_guide/X8-
1/Cisco-Expressway-SIP-Trunk-to-Unified-CM-Deployment-Guide-CUCM-8-9-and-X8-1.pdf
NEW QUESTION # 83
Which statement about scheduling Expressway backups is true?
- A. It is allowed from the application CLI of the Expressway only.
- B. It is allowed from the application GUI of the Expressway only.
- C. It is not supported on the application.
- D. It is allowed from the application CLI and GUI of the Expressway.
Answer: C
NEW QUESTION # 84
......
Verified 300-820 Dumps Q&As - 1 Year Free & Quickly Updates: https://examcollection.dumpsvalid.com/300-820-brain-dumps.html