Sign In
Home/Cisco/Implementing Cisco Collaboration Hybrid and Cloud Technologies (CLHCT) v2.0/Free questions

Implementing Cisco Collaboration Hybrid and Cloud Technologies (CLHCT) v2.0 — Free Practice Questions

10 free sample questions from a bank of 269, with the correct answers and explanations. No signup required — start practising right now.

1Which two statements about Expressway media traversal are true? (Choose two.)
  • Both Expressway Edge interfaces can be NATed.
  • The Unified Communications traversal zone can be used for Mobile and Remote Access.
  • Expressway Control is the traversal server installed in the DMZ.
  • The Expressway Edge must be put in a firewall DMZ segment.
  • Cisco Unified Communications Manager zone can be either traversal server or client.
Answer: B, D

The short version

B and D — MRA uses the UC traversal zone and Edge sits in the DMZ. That pairing reflects the standard traversal deployment for remote endpoints.

Key concepts in this question

  • Traversal client and server: Control initiates outward to Edge, which terminates inbound firewall sessions.
  • Unified Communications traversal zone: dedicated zone between Control and Edge for MRA signaling and media.
  • DMZ placement: Edge faces the internet while Control stays inside.

Why B and D are correct

Mobile and Remote Access is built on the Unified Communications traversal zone between Expressway-C and Expressway-E, so that zone is indeed used for MRA. The Edge node is the internet-facing traversal server and must reside in a firewall DMZ segment so only pinholes to the internal Control are opened.

Why the others are wrong

  • A. Only the Edge external interface is designed for NAT with Advanced Networking; both interfaces NATed is not supported practice.
  • C. Expressway-E in the DMZ is the traversal server, not Expressway-C, which stays internal as client.
  • E. The UCM zone to Control is a neighbor zone, not a traversal client or server pair.

300-820 exam tip — memory hook

Edge equals DMZ server, Control equals internal client, and MRA equals UC traversal zone.

2Which two types of information does Cisco Expressway back up? (Choose two.)
  • call records
  • log files
  • IP addresses
  • current call states
  • security certificates
Answer: A, E

The short version

A and E — Backups keep call records and certificates. Those persist across restores while transient and diagnostic data do not.

Key concepts in this question

  • Backup scope: restorable configuration, registration-relevant data, and security material.
  • Call records: call detail and history preserved for accounting continuity.
  • Certificates: server and trusted CA material needed to restore secure operation.

Why A and E are correct

A Cisco Expressway backup captures the data required to rebuild service identity and history: call records for continuity and security certificates so TLS, traversal, and MRA trust work immediately after restore. The excluded items are either ephemeral or separately collected diagnostics.

Why the others are wrong

  • B. Log files are diagnostics gathered via incident capture, not part of the restorable backup.
  • C. IP addresses are deployment addressing reapplied at install, not backed-up content.
  • D. Current call states are live transient sessions that cannot be snapshotted and restored.

300-820 exam tip — memory hook

Backup equals what rebuilds trust and history: certs and records; logs and live calls never restore.

3For a Mobile and Remote Access deployment, which server's certificate must include the Unified registration domain as a Subject Alternate Name?
  • Expressway-C server certificate
  • Cisco Unified Communications Manager server certificate
  • Expressway-E server certificate
  • Expressway-C and Expressway-E server certificate
Answer: C

The short version

C — The Expressway-E certificate carries the registration domain. Remote Jabber clients trust Edge, so its SAN must list the Unified domain.

Key concepts in this question

  • Unified registration domain: the enterprise domain remote endpoints use to register.
  • Subject Alternate Name: extra DNS names a TLS certificate is valid for.
  • Edge trust: external clients validate the Expressway-E certificate during MRA login.

Why C is correct

In Mobile and Remote Access, outside clients connect to Expressway-E first and validate its server certificate against the Unified registration domain they are registering to. Therefore the Expressway-E server certificate must include that domain as a Subject Alternate Name, or TLS validation and registration fail.

Why the others are wrong

  • A. The Expressway-C certificate faces internal servers, not the external clients validating the registration domain.
  • B. UCM certificates identify call-processing nodes, not the Edge entry point remote clients reach.
  • D. Requiring it on both overstates the need; the external validation point is Expressway-E.

300-820 exam tip — memory hook

External clients trust Edge, so the public registration domain SAN lives on the Expressway-E certificate.

4A Cisco Webex Hybrid Video Mesh Node can be installed in the DMZ and on the internal network.Which statement is true?
  • Webex Cloud supports either a DMZ-based Mesh Node for security or an internal-based Mesh Node for media control only.
  • Installing a Video Mesh Node in the DMZ requires you to open TCP and UDP port 4444 in your internal firewall for full clustering functionality.
  • Installing a Video Mesh Node in the DMZ requires the external firewall to allow UDP traffic from ANY port to the address of the Video Mesh Nodes via port 5004.
  • Using internal Video Mesh Node also works due to Mobile and Remote Access setup for Webex Teams clients. A DMZ node is added for extra security.
Answer: C

The short version

C — A DMZ Mesh Node needs inbound UDP to port 5004. That is the documented external-firewall media requirement.

Key concepts in this question

  • Video Mesh Node: cloud-managed media bridge for Webex meetings.
  • DMZ deployment: node reachable from Webex Cloud across the external firewall.
  • Media ports: UDP 5004 carries inbound media to DMZ nodes.

Why C is correct

When a Video Mesh Node sits in the DMZ, the external firewall must permit UDP traffic from any source port to the nodes on destination port 5004 so cloud media reaches the cluster. That precise any-to-5004 rule is the true statement among the choices and reflects the published port requirements.

Why the others are wrong

  • A. Webex Cloud does not split nodes into DMZ-security versus internal-media-only roles as described.
  • B. TCP and UDP 4444 on the internal firewall is not the stated full-clustering requirement for a DMZ node.
  • D. An internal node does not depend on MRA for Teams clients, and a DMZ node is not mere extra security.

300-820 exam tip — memory hook

DMZ Video Mesh media equals UDP 5004 inbound; memorize the port, not the 4444 distractor.

5A customer is migrating from an on-premises Cisco UCM deployment to Webex Calling and successfully converted the phone firmware from Enterprise to MPP. After a user is configured with Webex Calling professional license and the MPP phone is added with a MAC address, the endpoint fails to register. What is the reason?
  • The remote office's firewall is blocking specific Webex service ports
  • The user has not signed into the Webex account.
  • The phone must be added to the user before the license is assigned.
  • The Webex App is not installed on the user's PC or is not running.
Answer: A

The short version

A — Blocked Webex ports stop MPP registration. Converted phones must reach cloud services for onboarding and signaling.

Key concepts in this question

  • Enterprise to MPP conversion: moves the phone to cloud-managed firmware.
  • Webex Calling onboarding: phone reaches activation, configuration, and SIP services over the internet.
  • Firewall dependency: remote-office egress must allow the required Webex ports and URLs.

Why A is correct

The license and user setup are complete and firmware converted, so failure to register points to network reachability. MPP phones require specific Webex service ports and destinations for activation and SIP registration; a remote firewall blocking them produces exactly this symptom even with correct licensing and MAC assignment.

Why the others are wrong

  • B. MPP hardware registration does not require the user to sign into a Webex account first.
  • C. License-before-device ordering does not block SIP registration once both exist.
  • D. The Webex App on a PC is unrelated to a hardware MPP phone's SIP registration.

300-820 exam tip — memory hook

License plus MAC correct but MPP will not register equals firewall and Webex ports, not app or sign-in.

6Refer to the exhibit. A collaboration engineer creates an allow list test file for a Mobile and Remote Access deployment. Which lines are needed to format the test in the file correctly?
Implementing Cisco Collaboration Hybrid and Cloud Technologies (CLHCT) v2.0 question 6
  • https://myServer:8443/myPath.block, "my deployment", "a block test", GET
  • a block test:https:8443:GET "myServer/myPath":my deployment:block
  • a block test,https:8443,GET "myServer/myPath",my deployment:block
  • "my deployment", block, GET https://myServer:8443/myPath, "a block test"
Answer: D

The short version

D — Allow-list test line order is Deployment, result, Method + URL, Description. Exhibit fields map exactly to option D, so banked A is wrong order.

Key concepts in this question

  • MRA allow-list test file: CSV line used to test an allow-list rule
  • Field order: Deployment, ExpectedResult, Method + URL, Description
  • Exhibit mapping: URL + Port + Method combine into one token

Why D is correct

Option D is "my deployment", block, GET https://myServer:8443/myPath, "a block test". This matches the exhibit: Deployment = my deployment, ExpectedResult = block, Method = GET with URL = https://myServer/myPath plus Port 8443, Description = a block test. Only D preserves this order and quoting.

Why the others are wrong

  • A. Wrong field order starting with the URL and misplacing Deployment, Description, and Method.
  • B. Uses colon-separated syntax never used in the test file and scrambles all fields.
  • C. Uses comma-separated bare tokens without the required quoting and Method + URL combination.

300-820 exam tip

Memorize the allow-list test order as Deployment-result-Method/URL-Description.

7What are the steps to access the Service Setup Wizard during the first setup of the Expressway server to license the server?
  • Factory reset the Expressway server to pass from Smart Licensing to PAK-based licensing.
  • From the GUI of the Expressway server, go to Status> Overview> Run service setup.
  • Factory reset the Expressway server to pass from Expressway-C to Expressway-E.
  • From the GUI of the Expressway server, go to Maintenance> Option keys> First Setup Wizard.
Answer: B

The short version

B — Run service setup from Status and Overview. The first-setup wizard and licensing entry live behind that path.

Key concepts in this question

  • Service Setup Wizard: initial role, mode, and licensing workflow on a fresh Expressway.
  • GUI navigation: Status and Overview exposes the setup action.
  • Licensing: applied during or just after the wizard run.

Why B is correct

During first setup of an Expressway server, the supported path is the web GUI under Status, then Overview, then Run service setup. That launches the Service Setup Wizard where the administrator selects the service and applies licensing, which is exactly the access path the question asks for.

Why the others are wrong

  • A. A factory reset to switch licensing models is unnecessary and does not open the wizard.
  • C. A factory reset to change Control to Edge roles is unrelated to reaching the setup wizard.
  • D. Maintenance and Option keys manages release and option keys, not the First Setup Wizard entry point.

300-820 exam tip — memory hook

First setup wizard equals Status, Overview, Run service setup; option keys and resets are wrong doors.

8An administrator deployed the directory connector to synchronize the on-premises Active Directory with the Webex cloud and needs to map attributes from the AD to the corresponding attributes in the cloud. To which Webex cloud attribute must the user Account Control attribute be mapped to ensure that users are synced properly?
  • givenName
  • ds-pwp-account-disabled
  • SipAddresses:type=enterprise
  • displayName
Answer: B

The short version

B — Account Control maps to ds-pwp-account-disabled. That attribute carries the enabled-or-disabled state into the Webex cloud.

Key concepts in this question

  • Directory Connector: syncs on-premises Active Directory to Webex.
  • Attribute mapping: links AD source fields to cloud identity fields.
  • Account state: disabled accounts must stay disabled after sync.

Why B is correct

To sync users properly, the Active Directory user Account Control state must drive the cloud account-disabled flag. Mapping it to ds-pwp-account-disabled ensures disabled on-premises users arrive disabled in Webex, preventing unwanted activations and keeping lifecycle state consistent.

Why the others are wrong

  • A. GivenName maps the first name, not account status.
  • C. SipAddresses with enterprise type maps SIP routing addresses, not enablement state.
  • D. DisplayName maps the presentation name, which has no bearing on sync correctness for disabled users.

300-820 exam tip — memory hook

Disabled-account sync equals ds-pwp-account-disabled; name and SIP attributes never carry account state.

9Where are voice calls handled in a Cisco Jabber hybrid cloud-based deployment with Cisco Webex Platform Service?
  • Voice call use Cisco Unified Communications Manager for local calls and Webex Calling for external calls.
  • Voice calls use Webex Calling platform for call control and use hybrid media nodes for local conferencing.
  • Voice calls use local media nodes to keep traffic internal for internal traffic and use Webex Calling for external calls.
  • Voice calls use local Cisco Unified Communications Manager for all calls.
Answer: D

The short version

D — Local UCM keeps all call control in hybrid. Webex Platform Service adds messaging and presence while voice stays on-premises.

Key concepts in this question

  • Hybrid cloud deployment: on-premises call control plus cloud messaging services.
  • Jabber with Platform Service: IM, presence, and content in cloud, voice on UCM.
  • Media locality: signaling and media remain on the enterprise cluster.

Why D is correct

In a Jabber hybrid with Cisco Webex Platform Service, voice calls continue to use the local Cisco Unified Communications Manager for all calls. The cloud hosts platform services around the call, but call control, dial plan, and media handling do not move to Webex Calling, preserving on-premises voice behavior.

Why the others are wrong

  • A. Splitting local to UCM and external to Webex Calling describes a different cloud-calling mix, not this hybrid.
  • B. Webex Calling call control with hybrid media nodes is a cloud-calling architecture, not Jabber hybrid with Platform Service.
  • C. Using local nodes only for internal plus Webex Calling for external again moves control to cloud, contradicting the hybrid.

300-820 exam tip — memory hook

Hybrid plus Platform Service equals voice stays on UCM; Webex Calling control means a different deployment.

10An organization with a domain name of example.com.Which two SRV records are valid for a SIP and H.323 communication? (Choose two.)
  • _sips._tcp.example.com
  • _sips._udp.example.com
  • _h323ls._udp.example com
  • _h323ls._tcp.example.com
  • _collab-edge._tls.example.com
Answer: A, C

The short version

A and C — _sips._tcp and _h323ls._udp are the valid pair. Secure SIP uses TCP with TLS and H.323 location service uses UDP.

Key concepts in this question

  • SRV records: advertise service, protocol, and target hosts per domain.
  • _sips._tcp: secure SIP signaling over TLS on TCP.
  • _h323ls._udp: H.323 gatekeeper location service over UDP.

Why A and C are correct

For example.com, _sips._tcp.example.com correctly pairs the SIPS service with TCP transport, since secure SIP runs over TLS on TCP rather than UDP. Likewise _h323ls._udp correctly pairs H.323 gatekeeper discovery with UDP, matching the RAS location-service transport.

Why the others are wrong

  • B. _sips._udp is invalid because SIPS requires TLS over TCP, not UDP.
  • D. _h323ls._tcp is wrong because H.323 location service discovery uses UDP.
  • E. _collab-edge._tls serves Expressway MRA discovery, not generic SIP and H.323 communication.

300-820 exam tip — memory hook

SIPS equals TCP with TLS, H.323 location equals UDP; any UDP SIPS or TCP location choice is invalid.

Want the full bank of 269 questions for Implementing Cisco Collaboration Hybrid and Cloud Technologies (CLHCT) v2.0? See all practice exams.