exam questions

Exam 300-820 All Questions

View all questions & answers for the 300-820 exam

Exam 300-820 topic 1 question 62 discussion

Actual exam question from Cisco's 300-820
Question #: 62
Topic #: 1
[All 300-820 Questions]

Which two statements about Mobile and Remote Access certificate are true? (Choose two.)

  • A. Expressway Core can use private CA signed certificate.
  • B. You must upload the root certificates in the phone trust store.
  • C. Expressway must generate certificate signing request.
  • D. Expressway Edge must use public CA signed certificate.
  • E. The Jabber client can work with public or private CA signed certificate.
Show Suggested Answer Hide Answer
Suggested Answer: AE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
TestingAAgain
Highly Voted 2 years, 11 months ago
Selected Answer: AE
I meant to put A & E. Sorry.
upvoted 8 times
...
BangBang86
Highly Voted 4 years, 8 months ago
Jabber works fine with a private CA, and the ExpC can use a private CA. Those should be the right answers.
upvoted 5 times
...
iamnoone
Most Recent 1 month, 3 weeks ago
Selected Answer: AE
A. Expressway Core can use private CA signed certificate. > Yes it can use a private CA signed cert. But the Exp-E needs to trust it. Is it best practice? I guess not. Bin there, done that. B. You must upload the root certificates in the phone trust store. > Nope C. Expressway must generate certificate signing request. > No, it doesn't have too (must not). I believe you can use a private key generated and provided by a CA, and upload it manually via SCP. D. Expressway Edge must use public CA signed certificate. > No it must not. Can work with a private CA signed cert. E. The Jabber client can work with public or private CA signed certificate. > Yes it can. It will prompt the user to trust the certificate presented, if the root or intermidiate CA cert is not in the devices trust store. End of story. So A&E correct answers.
upvoted 1 times
...
ad5354f
6 months, 2 weeks ago
I think Collabinski is right. C and D are the answers I would prefer A. Expressway Core can use private CA signed certificate – While technically possible, this is not recommended for MRA, as clients connecting via the Edge would not trust a private CA. E. The Jabber client can work with public or private CA signed certificate – This is only partially true. The Jabber client can trust a private CA signed certificate if the root CA certificate is manually installed on the device, but for MRA via the Edge, a public CA is required for seamless operation.
upvoted 1 times
...
Panda_man
1 year, 6 months ago
Selected Answer: AD
A and D
upvoted 2 times
...
Testme1235
2 years ago
Selected Answer: AE
Which two statements about Mobile and Remote Access certificate are true? (Choose two.) A. Expressway Core can use private CA signed certificate. B. You must upload the root certificates in the phone trust store. C. Expressway must generate certificate signing request. D. Expressway Edge must use public CA signed certificate. E. The Jabber client can work with public or private CA signed certificate.
upvoted 1 times
...
Collabinski
2 years, 3 months ago
https://www.cisco.com/c/dam/en/us/td/docs/voice_ip_comm/expressway/config_guide/X8-9/Cisco-Expressway-Certificate-Creation-and-Use-Deployment-Guide-X8-9.pdf
upvoted 1 times
jagifoto
2 years, 2 months ago
Hi Collabinski , your answers are wrong.
upvoted 2 times
...
...
Collabinski
2 years, 3 months ago
Selected Answer: CD
The only server that is really required to be signed by a public CA is the Expressway-E. This is the only server that clients will see the certificate from when singing in via MRA therefore using a public CA will ensure that users do not have to manually accept the certificate. Certificate Generation Overview X.509 certificates may be supplied from a third party, or may be generated by a certificate generator such as OpenSSL or a tool available in applications such as Microsoft Certification Authority. Third-party certificates supplied by recognized certificate authorities are recommended, although Expressway deployments in controlled or test environments can use internally generated certificates. Certificate generation is usually a 3-stage process: ■ Stage 1: generate a private key ■ Stage 2: create a certificate request ■ Stage 3: authorize and create the certificate
upvoted 2 times
...
Collabinski
2 years, 3 months ago
I think C & D are correct. https://www.cisco.com/c/en/us/support/docs/unified-communications/expressway/213872-configure-and-troubleshoot-collaboration.html
upvoted 2 times
ad5354f
6 months, 2 weeks ago
i think , you're right.
upvoted 1 times
...
Collabinski
2 years, 3 months ago
Whether the cert is public or private, it looks like you must generate a CSR in Expressway before uploading the file.
upvoted 1 times
aocstr
1 year, 9 months ago
Not really, you can upload the certificate and private key generated by a CA without having to use CSR
upvoted 3 times
...
...
...
TestingAAgain
2 years, 11 months ago
Selected Answer: AD
I agree with the answers below. You can load a cert without a CSR as long as you also load the private key (you do this in clustering a lot), and you can use a private CA on the E as long as you're not going to have physical phones running through it.
upvoted 2 times
...
leigh1141
4 years, 2 months ago
Answer is A and D. Expressway C can use a public/private. Expressway E must use a private
upvoted 3 times
...
tclpjk
4 years, 9 months ago
answer should be A and D. For C, I think the key work is "can" or "must"
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago