CLCOR Infrastructure And Design Practice Question
When designing a secure collaboration network, what is the best practice for handling certificates in a CUCM and Expressway cluster?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a trusted third-party CA for all servers.
Using a trusted, third-party Certificate Authority (CA) ensures that all certificates are valid across both internal and external endpoints without security warnings.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use self-signed certificates on all nodes.
Why it's wrong here
Self-signed certificates cause trust issues and are difficult to manage.
- ✗
Disable certificate verification on all endpoints.
Why it's wrong here
This is a severe security vulnerability.
- ✗
Use the Publisher as the CA for the entire network.
Why it's wrong here
CUCM is not a root CA and cannot act as a trusted CA for all endpoints.
- ✓
Use a trusted third-party CA for all servers.
Why this is correct
Third-party CAs are trusted by all external and internal devices.
About these practice questions
One of 263 original CLCOR practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Cisco exam blueprint
This CLCOR practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLCOR exam.