nerdexam
Cisco

350-801 · Question #280

Refer to the exhibit. An administrator configures a secure SIP trunk on Cisco UCM. Which value is needed in the Secure Certificate Subject or Subject Alternate Name field to accomplish this task?

The correct answer is A. the fully qualified domain name of the remote device that is configured on the SIP trunk. When configuring a secure SIP trunk on Cisco UCM using TLS, the UCM must validate the certificate presented by the remote device. The 'Secure Certificate Subject or Subject Alternate Name' field tells UCM what to look for in that remote certificate. It must contain the FQDN of…

On-Premises Call Control

Question

Refer to the exhibit. An administrator configures a secure SIP trunk on Cisco UCM. Which value is needed in the Secure Certificate Subject or Subject Alternate Name field to accomplish this task?

Exhibit

350-801 question #280 exhibit

Options

  • Athe fully qualified domain name of the remote device that is configured on the SIP trunk
  • Bthe common name of the Cisco UCM CallManager certificate
  • Cthe common name of the remote device certificates
  • Dthe fully qualified domain name of all Cisco UCM nodes that run the CallManager service

How the community answered

(47 responses)
  • A
    85% (40)
  • B
    9% (4)
  • C
    4% (2)
  • D
    2% (1)

Explanation

When configuring a secure SIP trunk on Cisco UCM using TLS, the UCM must validate the certificate presented by the remote device. The 'Secure Certificate Subject or Subject Alternate Name' field tells UCM what to look for in that remote certificate. It must contain the FQDN of the remote device (as configured on the SIP trunk), because that is the value that will appear in the Subject or SAN field of the remote device's certificate. If the FQDN does not match, TLS mutual authentication fails and the secure trunk cannot establish. The UCM's own certificate CN (option B) is not relevant here, nor are the FQDNs of UCM nodes (option D), since this field is about authenticating the remote peer.

Topics

#SIP Trunk Security#Certificate Validation#Cisco UCM#TLS

Community Discussion

No community discussion yet for this question.

Full 350-801 Practice