300-820 Sample Questions & Answers
Four equally weighted areas include NAT traversal via ICE, STUN and TURN, dial-plan configuration on the Expressway Core, Webex Hybrid Services alongside Video Mesh architecture, and deployment or troubleshooting for Mobile and Remote Access.
Launch the full 300-820 simulator →Showing 10 of 20 free samples.
- Question 1Advanced
Key Concepts · Describe Expressway backup and restore procedure (stand alone and cluster)
A financial services firm is implementing a high-availability Expressway-C cluster. To meet compliance requirements, all configuration changes must be logged and a disaster recovery plan must be in place. When performing a backup on a clustered Expressway, what is the correct procedure?
Show answer & explanation
Correct answer: C
In an Expressway cluster, the configuration database is replicated from the primary (master) node to all other peer nodes. Therefore, performing a backup operation on the primary node is sufficient to capture the complete configuration for the entire cluster. This single backup file can be used to restore the configuration to the primary node, which will then replicate it to the other nodes upon re-clustering.
- Question 2Intermediate
Initial Expressway Configurations · Configure key Expressway settings
A collaboration engineer is setting up a new Expressway-E server in a DMZ. The server will be used for both MRA and B2B traffic. According to Cisco best practices, which network interface configuration is recommended for this deployment?
Show answer & explanation
Correct answer: C
The recommended and most common configuration for an Expressway-E in a DMZ is to use a single LAN interface with a single private IP address. The external firewall then performs Static 1:1 NAT to map a public IP address to the Expressway-E's private IP. This configuration simplifies routing and enhances security by not exposing the server's real IP address directly to the internet. The Expressway-E must be configured to be NAT-aware in this setup.
- Question 3Advanced
Initial Expressway Configurations · Configure toll fraud prevention on Expressway series (no custom CPL scripts)
Case Study: GlobalPharma Inc.
GlobalPharma Inc. is a multinational pharmaceutical company with a central headquarters in New York and major research hubs in London and Tokyo. They have an existing on-premises Cisco Unified Communications Manager (CUCM) cluster at version 12.5, which handles all internal voice and video calls. They are now planning a major B2B collaboration rollout to connect securely with dozens of research partners and regulatory agencies worldwide.
The network team has deployed a new Cisco Expressway-C and Expressway-E pair. The primary requirement is to prevent any unauthorized calls from traversing their Expressway infrastructure, specifically targeting the prevention of toll fraud. The Chief Information Security Officer (CISO) has explicitly forbidden the use of any custom Call Processing Language (CPL) scripts due to maintenance overhead.
The goal is to create a default routing policy that blocks all calls to external numbers unless they are explicitly allowed. Specifically, they want to route calls destined for known partner domains (e.g., partner.com) to a 'B2B_Partners' neighbor zone, while rejecting all other call attempts to unknown domains or E.164 numbers.
Which configuration on the Expressway-C would most effectively meet these toll fraud prevention requirements without using custom CPL scripts?
Show answer & explanation
Correct answer: C
This solution creates an explicit 'allow list' and a default 'deny' policy, which is a highly effective method for toll fraud prevention without CPL. The high-priority rules explicitly permit calls to known partners by routing them to the correct zone. The final, low-priority 'catch-all' rule (matching '.*') ensures that any call not matching a specific partner rule is stopped immediately. This directly prevents unauthorized calls to any other destination, fulfilling the CISO's requirement.
- Question 4AdvancedSelect 3
Initial Expressway Configurations · Configure a Business to Business (B2B) collaboration solution
An administrator is configuring a SIP trunk from a Cisco Expressway-C to a Cisco UCM cluster for a B2B solution. The UCM requires that all incoming SIP traffic on this trunk be encrypted. Which three settings are required to establish this secure connection? (Select THREE)
Show answer & explanation
Correct answers: A, C, E
Setting the TLS verify mode to 'On' on the Expressway-C's neighbor zone forces it to validate the UCM's certificate, which is essential for a secure connection.
This setting on the UCM security profile mandates that signaling for this trunk must be encrypted using TLS.
Port 5061 is the standard port for SIP over TLS (secure SIP). The UCM must be configured to listen for secure connections on this port.
- Question 5Intermediate
Mobile and Remote Access · Troubleshoot a Mobile and Remote Access (MRA) solution
A user reports that they are unable to connect to their company's collaboration services via MRA from their home office. The administrator suspects a DNS issue. Which command should the administrator ask the user to run from their home computer's command prompt to verify the crucial SRV record for MRA service discovery?
Show answer & explanation
Correct answer: D
The
nslookup -q=srv _collab-edge._tls.company.comcommand is used to query the public DNS for the specific SRV record that Jabber and other MRA clients use to discover the Expressway-E server. A successful response to this query is the first critical step in the MRA registration process. The _cisco-uds record is for internal service discovery, not external MRA. - Question 6Beginner
Mobile and Remote Access · Configure a Mobile and Remote Access (MRA) solution
When configuring the HTTP Allow List on a Cisco Expressway-C for an MRA deployment, what is the primary purpose of this feature?
Show answer & explanation
Correct answer: B
The HTTP Allow List is a crucial security feature. MRA clients use the Expressway pair as an HTTP proxy to access internal services like CUCM, IM&P, and Unity Connection. The Allow List on the Expressway-C ensures that it will only forward these proxy requests to a predefined list of trusted internal servers, preventing potential misuse of the proxy to access other unauthorized internal web resources.
- Question 7Advanced
Mobile and Remote Access · Troubleshoot a Mobile and Remote Access (MRA) solution
An MRA deployment suddenly fails after a network-wide certificate renewal. MRA clients can no longer register. The administrator checks the Expressway-E and sees that its server certificate has been correctly updated and includes the FQDN 'expressway.example.com' in the Subject Alternative Name (SAN). The UC Traversal Zone is also active. What is a common certificate-related cause for this failure?
Show answer & explanation
Correct answer: B
For successful TLS handshakes, each system must trust the Certificate Authority (CA) that issued the other system's certificate. In an MRA deployment, the Expressway-E needs to trust the CA that signed the CUCM/IM&P certificates, and the Expressway-C needs to trust the CA that signed the Expressway-E's certificate. If a new CA was used for the renewal, its root and any intermediate certificates must be explicitly uploaded to the trust stores of all communicating Expressway and UC servers. A missing trust anchor is a very common cause of failure after certificate renewals.
- Question 8Intermediate
Cisco Webex Technologies · Configure Webex Hybrid Services
A company is integrating their on-premises CUCM environment with Webex for Hybrid Calendar Service. The goal is to enable One Button to Push (OBTP) for on-premises registered video endpoints when users schedule meetings in their Office 365 calendars. Which component is responsible for polling Office 365 for meeting information and pushing it to the on-premises environment?
Show answer & explanation
Correct answer: B
The Calendar Connector is a software component installed on the Expressway-C. It registers with the Webex cloud and is authorized to access the company's Office 365 or Exchange environment. It polls for calendar events containing video conferencing details, processes them, and then uses the on-premises CUCM and TMS APIs to push the OBTP join button to the relevant endpoints.
- Question 9Intermediate
Cisco Webex Technologies · Describe the signaling and media flows used in a Cisco Webex Video Mesh deployment
An organization wants to optimize media traffic for its Webex meetings. They have a large office with hundreds of users who frequently join the same Webex meetings. To reduce WAN bandwidth consumption, they deploy a Webex Video Mesh Node on-premises. How does the Video Mesh Node achieve this optimization?
(Webex Cloud) ^ | (WAN Link) | v (Corporate LAN) [Video Mesh Node] [Endpoints]Show answer & explanation
Correct answer: B
The Webex Video Mesh Node acts as a local media cascade or bridge. When multiple on-premises endpoints join the same Webex meeting, their media streams terminate on the local Video Mesh Node. The node then establishes a single, optimized media connection to the Webex Cloud. This prevents each individual endpoint from sending its own media stream over the WAN link, significantly reducing outbound bandwidth consumption.
- Question 10IntermediateSelect 2
Cisco Webex Technologies · Configure user management integrations (directory services and SSO)
A university is setting up Webex and needs to automatically provision accounts for all its students and faculty from its on-premises Active Directory. They also want to enable Single Sign-On (SSO) so users can log in with their university credentials. Which two components are required to achieve both directory synchronization and SSO? (Select TWO)
Show answer & explanation
Correct answers: A, C
The Cisco Directory Connector is the software installed on-premises that synchronizes users and groups from Active Directory to the Webex Control Hub.
SSO for Webex is achieved by establishing a trust relationship between the Webex Control Hub (the Service Provider) and a SAML 2.0 compliant Identity Provider (IdP). The IdP is responsible for authenticating the users.
Ready for the real thing?
The full 300-820 simulator has every exam-style question, timed mode, and instant scoring.