nerdexam
Avaya

71301T · Question #9

You are setting up the SIP connection between Avaya Aura® Messaging (AAM) and the Avaya Aura® Core, and the information you have entered for the Far-end connection is: What should you conclude from…

The correct answer is C. A Security Certificate from the same Certificate Authority as the other Avaya Aura® components. When TLS is configured on port 5061 for a SIP connection, the conclusion is that a Security Certificate from the same Certificate Authority (CA) as the other Avaya Aura® components is required - because TLS mutual authentication depends on all endpoints trusting the same CA…

Implement Avaya Aura Messaging

Question

You are setting up the SIP connection between Avaya Aura® Messaging (AAM) and the Avaya Aura® Core, and the information you have entered for the Far-end connection is: What should you conclude from all this information?

Options

  • AThe connection cannot work because 5061 is not the Well-known port corresponding to TLS by
  • BThere will be conflicts in the TLS connections given that 5061 is a well-known port that other
  • CA Security Certificate from the same Certificate Authority as the other Avaya Aura® components,
  • DThe IP address is wrong because its range does not correspond to a valid TLS-compatible IP

How the community answered

(44 responses)
  • A
    7% (3)
  • B
    14% (6)
  • C
    75% (33)
  • D
    5% (2)

Explanation

When TLS is configured on port 5061 for a SIP connection, the conclusion is that a Security Certificate from the same Certificate Authority (CA) as the other Avaya Aura® components is required - because TLS mutual authentication depends on all endpoints trusting the same CA, which is the standard PKI model within an Avaya Aura® deployment.

Why the distractors are wrong:

  • A is incorrect because 5061 is the IANA-assigned well-known port for SIP over TLS - it's the correct port, not an invalid one.
  • B is incorrect because using a well-known port is standard and expected; it does not inherently cause conflicts.
  • D is incorrect because there is no such concept as a "TLS-compatible IP address range" - TLS is a transport-layer protocol independent of IP address ranges.

Memory tip: Think "TLS = Trust" - whenever you see port 5061 (SIP/TLS), your immediate next thought should be certificates and CA trust chains. In any Avaya Aura® environment, components authenticate each other via TLS certificates, so a shared CA is always a prerequisite for TLS-secured SIP to function.

Topics

#SIP Configuration#TLS Certificates#Avaya Aura Messaging#Security/PKI

Community Discussion

No community discussion yet for this question.

Full 71301T Practice