nerdexam
Cisco

300-820 · Question #22

Refer to the exhibit. An Expressway-C and Expressway-E are configured for B2B calling and the Expressway-E zone is set to TLS Verify Currently, calls do not reach the Expressway-C. The Traversal…

The correct answer is C. Add a server certificate to the Expressway-C that is signed by a certificate authority. When the Expressway-E zone is configured with TLS Verify mode, it validates the certificate presented by the connecting peer (Expressway-C). If the Expressway-C only has a self-signed certificate, the Expressway-E will reject the connection because the certificate is not…

Cisco Expressway for Collaboration

Question

Refer to the exhibit. An Expressway-C and Expressway-E are configured for B2B calling and the Expressway-E zone is set to TLS Verify Currently, calls do not reach the Expressway-C. The Traversal Client zone on the Expressway-C for B2B reports the information in the exhibit for the Peer 1 address. Which action resolves this error?

Exhibit

300-820 question #22 exhibit

Options

  • AConfigure the Expressway-C Traversal Client zone Peer 1 address with the fully qualified
  • BConfigure the Expressway-C Traversal Client zone transport protocol with TCP.
  • CAdd a server certificate to the Expressway-C that is signed by a certificate authority.
  • DAdd an intermediate certificate to the Expressway-C that is signed by a certificate authority.

How the community answered

(16 responses)
  • A
    13% (2)
  • C
    81% (13)
  • D
    6% (1)

Explanation

When the Expressway-E zone is configured with TLS Verify mode, it validates the certificate presented by the connecting peer (Expressway-C). If the Expressway-C only has a self-signed certificate, the Expressway-E will reject the connection because the certificate is not trusted. The error shown in the exhibit on the Traversal Client zone indicates a TLS certificate verification failure. Option C is correct: adding a server certificate to Expressway-C signed by a trusted Certificate Authority (CA) resolves this, as the Expressway-E will then be able to verify and trust the certificate. Option A (FQDN for peer address) relates to hostname resolution, not certificate trust. Option B (changing to TCP) would remove encryption, which is not a valid fix. Option D (intermediate cert) alone is insufficient if the server certificate itself is self-signed.

Topics

#Expressway#TLS#Certificates#Traversal Zone

Community Discussion

No community discussion yet for this question.

Full 300-820 Practice