Infrastructure and Design
Drill 14 practice questions focused entirely on Infrastructure and Design for the Cisco 350-801 exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.
A network engineer is deploying a Cisco Unified Border Element (CUBE) between an internal Cisco Unified Communications Manager cluster and a new SIP service provider. During testing, calls fail because the ITSP sends SIP messages with a Diversion header format that CUCM does not accept, and the provider requires a specific From-header domain that differs from CUCM's internal IP-based host. Which capability of CUBE should the engineer use to resolve these SIP interoperability issues without changing the CUCM or provider configuration?
A company is migrating from PRI circuits to a SIP trunk provided by an Internet Telephony Service Provider (ITSP). The service provider's SIP signaling uses a different codec set and dialing format than the internal Cisco Unified Communications Manager cluster, and security requires that the internal network topology not be exposed to the provider. Which device should the engineer deploy at the network edge to meet these requirements?
You are planning a standard (L2) upgrade of a Cisco Unified Communications Manager cluster consisting of one publisher, two call-processing subscribers, and one dedicated TFTP subscriber. To minimize risk and follow Cisco's recommended cluster upgrade sequence, in what order should the nodes have the new software installed to the inactive partition?
A collaboration engineer is performing a major upgrade of a Cisco Unified Communications Manager cluster running an active/inactive partition design. After installing the upgrade COP/ISO on the publisher and all subscribers, the new software is loaded into the inactive partition while production continues on the active partition. Management asks how the cluster will actually begin running the new version with minimal service disruption. Which action correctly transitions the cluster to the new software?
A collaboration engineer enables mixed-mode on a CUCM cluster using the Tokenless CTL method (utils ctl set-cluster mixed-mode). After the cluster restarts, secure phones fail to register and report 'Trust List Update Failed' when downloading their configuration. Manual inspection shows phones still hold an older CTL file signed by physical USB security tokens from a previous deployment. What is the root cause of the registration failure?
During a planned Cisco Unified Communications Manager cluster upgrade, an administrator uploads a new ISO to the SFTP server and initiates the install from the publisher's OS Administration page. The upgrade process halts with an error indicating the checksum or file validation failed, and the readiness check will not proceed. Which action should the administrator take to resolve this before continuing the cluster upgrade?
A company deploys Cisco Expressway-C and Expressway-E to enable business-to-business (B2B) video calls with external partner organizations over the internet. During deployment, the network administrator asks which edge device should be placed in the DMZ and what mechanism allows media and signaling to traverse the firewall without requiring inbound ports to be opened toward the internal network. Which statement correctly describes the design?
A network architect is documenting the Cisco Collaboration edge architecture for a new deployment. The design must allow internal Jabber and desk phone users to reach the PSTN through a service provider SIP trunk, and also allow remote employees to register their Jabber clients securely without a VPN. Which statement correctly describes the roles of the edge devices required to meet both requirements?
A remote engineer reports that Jabber successfully logs in through MRA and can search the corporate directory, but calls fail to establish with a secure SIP profile applied. Non-secure phones registering internally work fine. Packet captures on the Expressway-C show the SIP INVITE reaching CUCM, but CUCM logs indicate a failed TLS handshake for the encrypted signaling channel. Which action most directly resolves the secure call failure?
A newly deployed batch of Cisco IP phones fails to register with a CUCM cluster running in mixed mode (secured). Phones that were already registered before enabling mixed mode continue to work normally. Packet captures from a failing phone show the TFTP download of the ITL file completing successfully, but the TLS handshake to CUCM fails with a certificate validation error. The phone's displayed date is January 1, 1970. What is the MOST likely root cause?
A company uses Expressway-C and Expressway-E for business-to-business (B2B) video calls. Outbound calls to a partner domain (partner.example.com) fail immediately, while inbound calls from that partner succeed. From the Expressway-C, an administrator can ping the partner's Expressway-E by IP address. A packet capture shows no SIP INVITE ever leaves the local network for outbound attempts. What is the MOST likely cause of the outbound call failure?
A remote employee reports that Cisco Jabber cannot sign in over Mobile and Remote Access (MRA), but the same account works fine when connected to the corporate VPN. Packet captures show Jabber successfully resolving the internal home cluster address, but it never reaches the Expressway-E. The administrator confirms the _collab-edge SRV record is missing from the external DNS. What is the most likely effect of this missing record, and what should the administrator do?
A batch of new Cisco IP phones at a branch site fails to register with CUCM. The phones power up via PoE and show an IP address in the data VLAN subnet (10.10.20.0/24) instead of the voice VLAN subnet (10.10.30.0/24). Data PCs on the same switch ports work normally, and CUCM is reachable from the data VLAN. Which action most likely resolves the registration problem?
You configured a secure SIP trunk between Cisco Unified Communications Manager (CUCM) and a Cisco Expressway-C using TLS. Calls over the trunk fail to establish, and the CUCM SDL trace shows a TLS handshake failure with the reason 'certificate verify failed'. The SIP Trunk Security Profile on CUCM is set to Encrypted with 'X.509 Subject Name' populated. Both nodes' certificates are signed by the same enterprise CA, which is loaded into each server's trust store. What is the MOST likely cause of the failure?
More 350-801 practice
Keep going with the other Cisco CCNP Collaboration CLCOR (350-801) domains, or take a full timed mock exam.
← Back to 350-801 overview