Cisco 300-820 exam practice questions

Which two considerations must be made when using Expressway media traversal? (Choose two.)
A. It is possible to NAT both Expressway-E interfaces
B. The Unified Communications traversal zone should be used for MRA
C. The Expressway-E must be put in a firewall DMZ segment
D. Expressway Control is the traversal server installed in the DMZ
E. Cisco UCM zone should be either traversal server or client


In a Mobile and Remote Access deployment, where must communications be encrypted with TLS?
A. Cisco Expressway-E and endpoints outside the enterprise
B. Cisco Expressway-C, Cisco Unified Communications Manager, and IMandP
C. Cisco Expressway-C, Cisco Expressway-E, and Cisco Unified Communications Manager
D. Cisco Expressway-C, Cisco Expressway-E, and endpoints outside the enterprise


Which SIP media encryption mode is applied by default for newly created zones in the Cisco Expressway?
A. Off
B. Best Effort
C. Auto
D. Force Encrypted


A Cisco Webex Hybrid Video Mesh Node can be installed in the DMZ and on the internal network.
Which statement is true?
A. Webex Cloud supports either a DMZ-based Mesh Node for security or an internal-based Mesh Node for media
control only.
B. Installing a Video Mesh Node in the DMZ requires you to open TCP and UDP port 4444 in your internal firewall for full clustering functionality.
C. Installing a Video Mesh Node in the DMZ requires the external firewall to allow UDP traffic from ANY port to the
address of the Video Mesh Nodes via port 5004.
D. Using internal Video Mesh Node also works due to Mobile and Remote Access setup for Webex Teams clients. A
DMZ node is added for extra security.


Which two licenses are required for the B2B feature to work? (Choose two.)
A. Traversal Server
B. TURN Relays
C. Rich Media Sessions
D. Advanced Networking
E. Device Provisioning


Which two statements about Mobile and Remote Access certificate are true? (Choose two.)
A. Expressway Core can use private CA signed certificate.
B. You must upload the root certificates in the phone trust store.
C. Expressway must generate certificate signing request.
D. Expressway Edge must use public CA signed certificate.
E. The Jabber client can work with public or private CA signed certificate.


An engineer is deploying an Expressway solution for the SIP domain Which SRV record should be
configured in the public DNS to support inbound B2B calls?


QUESTION 8cisco 300-820 exam questions q8

Refer to the exhibit. Mobile Cisco Jabber cannot register with on-premises Cisco Unified Communications Manager
using Mobile and Remote Access. Some logs were captured on Expressway Edge.
Which action corrects this problem?
A. Ensure that the peer address does not match the Common Name on certificate.
B. Ensure that the _cisco-uds SRV record has been configured.
C. Ensure that the credential has been entered correctly.
D. Ensure that the SIP domains are added on Expressway Core.


QUESTION 9cisco 300-820 exam questions q9

Refer to the exhibit. Calls to locally registered endpoints are failing. At present, there are two endpoints registered
locally to this Expressway. An H.323 endpoint with an alias of “EndpointA” is registered, and a SIP endpoint with an
alias of “[email protected]” is also registered. How is this issue resolved?
A. The dialplan must be redesigned to use the transforms to convert the alias into SIP URI format and then use
separate search rules for each format that needs to be dialed within the local zone.
B. The calls are failing because there are insufficient licenses. Additional licenses must be installed for the Expressway to route these calls.
C. The current search rule does not match the call, so the search rule must be modified to include a SIP Variant of
D. Calling parties are placing calls with the wrong domain. End-users must be instructed not to use the pod1.local
domain as that is owned by the local system. Calls to any other domain would work.


Which mode should be used when Call Policy is configured on Expressways?
A. extended CPL
B. local CPL, policy service, and off
C. on
D. remote CPL


What happens to the encrypted signaling traffic of a collaboration device if you place it inside a firewall with private IP addresses and try to make a call over IP without any collaboration infrastructure?
A. The signaling makes it back to the endpoint because the firewall is an application layer gateway and provides
address translation.
B. Encrypted IP traffic for collaboration devices always is trusted by the firewall.
C. The signaling does not make it back to the endpoint because the firewall cannot inspect encrypted traffic.
D. The signaling makes it back to the endpoint because the endpoint sent the private address to the external endpoint.


When determining why Mobile and Remote Access to Cisco TelePresence equipment does not work anymore for an organization. There are several administrators and configuration changes could have happened without anyone
knowing. Internal communication seems to be working, but no external system can register or call anywhere. Gathering symptoms, you also discover that no internal systems can call out either.
What is TraversalZone missing that causes this issue?
A. link to the DefaultZone
B. pipe to the DefaultZone
C. SIP trunk to the DefaultZone
D. route pattern to the DefaultZone


QUESTION 13cisco 300-820 exam questions q13

Refer to the exhibit. Which two outbound connections should an administrator configure on the internal firewall?
(Choose two.)
A. XMPP: TCP 7400
B. SIP: TCP 7001
C. SIP TCP 5061
D. Media: UDP 36012 to 59999
E. HTTPS: TCP 8443


QUESTION 14cisco 300-820 exam questions q14

Refer to the exhibit. An ISDN gateway is registered to Expressway-C with a prefix of 9 and/or it has a neighbor zone
specified that routes calls starting with a 9. Which value should be entered into the “Source” field to prevent toll fraud regardless at origin of the call?
A. Traversal Zone
B. Any
C. Neighbor Zone
D. All


How does an administrator configure an Expressway to make sure an external caller cannot reach a specific internal
A. block the call with a call policy rule in the Expressway-E
B. add the specific URI in the firewall section of the Expressway and block it
C. configure FAC for the destination alias on the Expressway
D. add a search rule route all calls to the Cisco UCM
