exam questions

Exam 300-820 All Questions

View all questions & answers for the 300-820 exam

Exam 300-820 topic 1 question 119 discussion

Actual exam question from Cisco's 300-820
Question #: 119
Topic #: 1
[All 300-820 Questions]

An administrator configures a secure SIP trunk in Cisco UCM to Expressway-C. The SIP trunk fails to become active, and an examination of a packet capture finds that the TLS handshake failed with a “Certificate Unknown” error from Cisco UCM. To allow the Cisco UCM to trust the Expressway-C and establish a TLS connection, the administrator will upload the Expressway server certificate to the trust store. To which trust store must the certificate be uploaded?

  • A. tomcat-trust
  • B. CallManager-trust
  • C. TVS-trust
  • D. ipsec-trust
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
jonycakes
3 weeks, 5 days ago
Selected Answer: B
Answer B: When configuring a secure SIP trunk (TLS) between Cisco Unified Communications Manager (UCM) and Cisco Expressway-C, the Cisco UCM must trust the certificate presented by the Expressway-C during the TLS handshake. The certificate for Expressway-C should be uploaded to the CallManager-trust trust store in Cisco UCM, which is used for managing and storing the certificates for secure communications, including SIP trunks. The other trust stores are used for different purposes: - tomcat-trust: This is used for Tomcat-based applications (web services), not for SIP trunks.
upvoted 1 times
...
ocero
3 months ago
A and B Cisco Unified Communications Manager Certificates The two Cisco Unified Communications Manager certificates that are significant for Mobile and Remote Access are the CallManager certificate and the tomcat certificate. These are automatically installed on the Cisco Unified Communications Manager and by default they are self-signed and have the same common name (CN).
upvoted 1 times
...
Panda_man
9 months, 1 week ago
Selected Answer: B
B is correct
upvoted 2 times
...
Collabinski
1 year, 5 months ago
Selected Answer: B
"the administrator will upload the Expressway server certificate to the trust store" (CUCM) https://www.cisco.com/c/dam/en/us/td/docs/voice_ip_comm/expressway/config_guide/X8-1/Cisco-Expressway-SIP-Trunk-to-Unified-CM-Deployment-Guide-CUCM-8-9-and-X8-1.pdf
upvoted 1 times
...
Collabinski
1 year, 5 months ago
Loading server and trust certificates on Unified CM Certificate management for Unified CM is performed in the Cisco Unified OS Administration application. All existing certificates are listed under Security > Certificate Management. Server certificates are of type certs and trusted CA certificates are of type trust-certs. Unified CM server certificate By default, Unified CM has a self-signed server certificate CallManager.pem installed. We recommend that this is replaced with a certificate generated from a trusted certificate authority. Unified CM trusted CA certificate To load the root CA certificate of the authority that issued the Expressway certificate (if it is not already loaded): 1. Click Upload Certificate/Certificate chain. 2. Select a Certificate Name of CallManager-trust. 3. Click Browse and select the file containing the root CA certificate of the authority that issued the Expressway certificate. 4. Click Upload File. Repeat this process on every Unified CM server that will communicate with Expressway. Typically this is every node that is running the CallManager service.
upvoted 1 times
...
neverknow
1 year, 6 months ago
Tomcat-Trust = tls verify callmanager-trust = secure device registration In the question it's talking about the initial SIP Trunk standup, not device registration. So i'd lean toward Tomcat-trust A. https://www.cisco.com/c/en/us/support/docs/unified-communications/expressway/213872-configure-and-troubleshoot-collaboration.html#anc13
upvoted 4 times
grnmad
5 months, 2 weeks ago
I agree, configure Trust Between CUCM and Expressway-C The concept, in this case, is exactly the same as between Expressway-C and Expressway-E. The CUCM must first trust the server certificate of the Expressway-C. That means that on the CUCM, the intermediates and root certificates of the Expressway-C need to be uploaded as a tomcat-trust certificate for the TLS verify feature and a CallManager-trust for secure device registrations. To achieve this, navigate to Cisco Unified OS Administration in the upper right of the CUCM web GUI, then Security> Certificate Management. Here you can click Upload Certificate/Certificate Chain and select the correct trust format or click Find to see the list of currently uploaded certificates.
upvoted 1 times
...
...
Ol_Mykhailiuk
1 year, 7 months ago
The question is marked with an asterisk, since the correct answer here, as far as I'm concerned, is AB: Upload the root and intermediate (if there are any) certificates on CUCM: In the new window, start to upload the root.pem certificate you got from Step 1. Upload it first as 'Tomcat Trust' Click or select the 'Upload' button and next you must see "Success: Certificate Uploaded". Ignore the message about restart Tomcat for now. Upload the same root.pem file now as 'CallManager-trust' for the 'Certificate Purpose'. Repeat previous steps (upload as 'tomcat-trust' and 'CallManager-trust') for all the intermediate certificates you have. https://www.cisco.com/c/en/us/support/docs/unified-communications/expressway/217748-upload-the-root-and-intermediate-certifi.html
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago