210-065 · Question #115
An engineer is configuring mobile and remote access. Which three configuration tasks should the engineer perform? (Choose three.)
The correct answer is B. Add the Cisco Unified Communications Manager root certificate to the Cisco Expressway Core C. Enable TLS verify mode for the traversal zone. D. Add the Cisco Unified Communications domain before enabling services on the Cisco. MRA configuration on Cisco Expressway requires adding the CUCM certificate, enabling TLS verify on the traversal zone, and registering the UC domain before enabling services.
Question
An engineer is configuring mobile and remote access. Which three configuration tasks should the engineer perform? (Choose three.)
Options
- AManually configure a Cisco Unified Communications Manager neighbor zone on the Cisco
- BAdd the Cisco Unified Communications Manager root certificate to the Cisco Expressway Core
- CEnable TLS verify mode for the traversal zone.
- DAdd the Cisco Unified Communications domain before enabling services on the Cisco
- EEnable H.323 on the Cisco Unified Communications Manager neighbor zone.
- FAdd the Cisco Expressway Edge root certificate to the Cisco Unified Communications Manager
How the community answered
(32 responses)- A16% (5)
- B75% (24)
- E3% (1)
- F6% (2)
Why each option
MRA configuration on Cisco Expressway requires adding the CUCM certificate, enabling TLS verify on the traversal zone, and registering the UC domain before enabling services.
MRA relies on automatic CUCM discovery via DNS SRV records, so manually creating a CUCM neighbor zone on Expressway is not a required or recommended MRA configuration step.
Adding the CUCM root certificate to Expressway-C allows Expressway to authenticate CUCM's identity during TLS connections, which is mandatory for establishing a secure MRA signaling path.
Enabling TLS verify mode on the traversal zone between Expressway-C and Expressway-E enforces mutual certificate validation, a required security control in MRA deployments.
The Unified Communications domain must be added to Expressway-C before enabling MRA services so that the system can perform DNS SRV-based automatic discovery of CUCM and other UC infrastructure.
MRA uses SIP as its signaling protocol between Expressway and CUCM; H.323 is not used in MRA and enabling it on the neighbor zone has no effect on MRA functionality.
Adding the Expressway-E root certificate to CUCM is not a standard MRA configuration requirement; certificate trust in MRA flows from CUCM into Expressway-C, not the reverse.
Concept tested: Cisco Expressway Mobile and Remote Access configuration tasks
Source: https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X12-5/exwy_b_mra-expressway-deployment-guide.html
Topics
Community Discussion
No community discussion yet for this question.