exam questions

Exam 350-801 All Questions

View all questions & answers for the 350-801 exam

Exam 350-801 topic 1 question 156 discussion

Actual exam question from Cisco's 350-801
Question #: 156
Topic #: 1
[All 350-801 Questions]

Refer to the exhibit.

An administrator configures a secure SIP trunk on Cisco UCM. Which value is needed in the Secure Certificate Subject or Subject Alternate Name field to accomplish this task?

  • A. the common name of the remote device certificates
  • B. the fully qualified domain name of all Cisco UCM nodes that run the CallManager service
  • C. the common name of the Cisco UCM CallManager certificate
  • D. the fully qualified domain name of the remote device that is configured on the SIP trunk
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Slushed
Highly Voted 3 years ago
Selected Answer: D
The correct answer is D. https://video.cisco.com/video/6196744148001
upvoted 12 times
...
CiscoSailor
Highly Voted 1 year, 10 months ago
Selected Answer: A
I think this is A. Yes, CN is often the same as FQDN, but not always. A is the better answer. This field refers to the certificate of the remote end, not the local CUCM, so B & C are incorrect.
upvoted 5 times
[Removed]
1 year, 9 months ago
NO, MR CHATGPT!
upvoted 1 times
...
...
G0y0
Most Recent 2 months, 1 week ago
Selected Answer: A
Correct answer is A. It is useless to specify the FQDN if it is not explicitly stated in the CN of the peer's certificate. If you put the FQDN, the CUCM will check if the FQDN is in the peer's certificate. If the FQDN is not in the CN, the CUCM will reject transactions with the peer. You need to put there what is specified in the CN of the peer's certificate, be it the FQDN, the domain, the hostname, the IP address, etc. Common Name (CN) is not synonym of FQDN. For example, if you do a TLS connection with an Expressway, the subject name or an subject alternate name provided, by the Expressway in its certificate. For Expressway clusters, ensure that this list includes all of the names contained within all of the peers' certificates. To specify multiple X.509 names, separate each name by a space, comma, semicolon or colon. So , correct answer is A.
upvoted 2 times
G0y0
2 months, 1 week ago
Reference: "Preferred Architecture for Cisco Collaboration 12.x Enterprise On-Premises Deployments", Chapter 7: Security, in the section "SIP Trunk Encryption", yo can read what is exactly X.509 Subject Name, that is "The common name (CN) of the remote party." and some examples.
upvoted 1 times
G0y0
2 months, 1 week ago
Table 7-11 SIP Trunk Security Profile Parameters for Secure SIP Trunks
upvoted 1 times
...
...
...
DDPRE
2 months, 3 weeks ago
Selected Answer: D
As per Copilot: For configuring a secure SIP trunk on Cisco Unified Communications Manager (UCM), the correct value needed in the Secure Certificate Subject or Subject Alternate Name field is: D. the fully qualified domain name of the remote device that is configured on the SIP trunk. This ensures that the certificate matches the domain name of the remote device, which is essential for establishing a secure TLS connection.
upvoted 1 times
...
decdca7
5 months, 3 weeks ago
Selected Answer: A
Common name or SAN that is how certificates work.
upvoted 1 times
...
cyberknock
7 months, 4 weeks ago
Selected Answer: A
A - Even the field Name indicates that the Common Name is meant...
upvoted 2 times
cyberknock
7 months, 4 weeks ago
C sorry
upvoted 1 times
...
...
JoeC716
12 months ago
Selected Answer: D
Agree with Slushed - Look at 7:40 https://www.youtube.com/watch?v=mTEtVOHKf20
upvoted 2 times
G0y0
2 months, 1 week ago
In the reference you provide, you are talking about a CUC certificate, which does match the FQDN, but the question does not tell you what is on the other side, whether it is a UNITY, an IM&T, a CUBE, a Gateway, an Expressway-C, or a cluster, or an Oracle SBC, etc. etc. etc. FQDN is not the same as CN. If the question said that the remote device is a CUC, D would be correct. But assuming that it is the FQDN of a remote device that we do not know, the first thing we have to see is the CN and in this case it is precisely the one that is not used, therefore it is A. It is recommended that if you are going to cite a source, it is valued. But please, interpret and read the source correctly before advertising it.
upvoted 1 times
...
...
TheBabu
1 year ago
Selected Answer: A
If the FQDN that is configured on the SIP trunk is not present in the certificate, the TLS connection fails. You gotta use an FQDN that exists on the remote device's certificate, that's how certificate validation works.
upvoted 2 times
...
Daved90
1 year, 1 month ago
Selected Answer: A
FQDN != CN or SAN, often it is but not always
upvoted 3 times
...
Kabimas66
1 year, 1 month ago
from https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/security/11_5_1_SU3/cucm_b_security-guide-1151su3/cucm_b_security-guide-1151su3_chapter_011000.html, you can read explanation of "Secure Certificate Subject or Subject Alternate Name" field of SIP Trunk Security Profile Settings It looks answer is C
upvoted 1 times
...
SergeantDuty
1 year, 10 months ago
Selected Answer: A
It's always the CN of the remote certificate. CN can bei the FQDN or Hostname or a MAC in case of Analogue Gateways. e.g. The CN is configured at the trustpoint configuration (Cisco IOS).
upvoted 5 times
[Removed]
1 year, 9 months ago
NO, MR CHATGPT!
upvoted 2 times
SergeantDuty
1 year, 9 months ago
Have a Look at this Link (https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/200180-Configure-SIP-TLS-Trunk-on-the-Communica.html ). Section: Step 8. Create SIP Trunk Security Profiles. Here you can See that it is the CN of the remote Host/devices. At the screenshots below you can See that a CN is not always a FQDN. In this example it is CUCM10.
upvoted 3 times
...
...
...
TeeKay25
1 year, 12 months ago
Selected Answer: B
B is the correct answer
upvoted 1 times
[Removed]
1 year, 9 months ago
NO, MR CHATGPT!
upvoted 1 times
...
...
azizkasmir
2 years, 4 months ago
Selected Answer: D
https://www.google.com/url?sa=t&rct=j&q=&esrc=s&source=web&cd=&cad=rja&uact=8&ved=2ahUKEwik1rGj9PT7AhVTH7cAHUcHBFgQFnoECBMQAw&url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DT1IEHMCQPb0&usg=AOvVaw0_ghphBkOhI3Ob2_-mXaZI
upvoted 4 times
Daved90
1 year, 1 month ago
FQDN =! CN in a certificate, A is more correct
upvoted 1 times
...
...
KZG
2 years, 8 months ago
If you have a Unified Communications Manager cluster or if you use SRV lookup for the TLS peer, a single trunk may resolve to multiple hosts, which results in multiple Secure Certificate Subject or Subject Alternate Name for the trunks https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/security/12_5_1/cucm_b_security-guide-1251/cucm_b_security-guide-1251_chapter_011000.html
upvoted 1 times
...
Piji
2 years, 8 months ago
Selected Answer: D
Correct answer is D.
upvoted 2 times
...
AJBELL14
2 years, 9 months ago
Selected Answer: B
I couldn't find specific info on the cisco site. As per other forums - Option B - the fully qualified domain name of all Cisco UCM nodes that run the CallManager service is the right answer
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago