What is the main difference between Cisco Jabber and Cisco Jabber Video for TelePresence?
A. Cisco Jabber registers to the Cisco Unified Communications Manager, whereas Cisco Jabber Video for TelePresence registers to the VCS.
B. Cisco Jabber Video for TelePresence registers to Cisco Unified Communications Manager, whereas Cisco Jabber registers to the VCS.
C. Cisco Jabber has no video calling capabilities, whereas Cisco Jabber Video for TelePresence has video capabilities.
D. Cisco Jabber has no presence capabilities, whereas Cisco Jabber Video for TelePresence has presence
E. There is no difference between Cisco Jabber and Cisco Jabber Video for TelePresence. They should not coexist in the same network.
210-065 exam Correct Answer: A

When the Cisco Jabber usertries to call extension 3501, Cisco Jabber never places the call No errors or messages are seen and no reordertone is heard. Assuming that the Cisco Jabber calling search space is configured correctly in Cisco Unified Communications Manager, which of these could be causing this issue?
A. CTI for the end user must be enabled.
B. Cisco Jabber must be reconfigured for desktop mode.
C. The username or password is misconfigured in Cisco Jabber.
D. The Cisco Jabber Advanced Phone Settings are misconfigured.
E. Cisco Jabber does not have the correct phone button template and hence has not registered to the Cisco Unified Communications Manager.
F. The called user presence status is unknown.
G. The called user has not been added as a contact in Cisco Jabber.
Correct Answer: D

A customer requests a configuration that enables users to easily add a third party to an existing call. The environment contains only three Cisco TelePresence C40 codecs and one Cisco VCS. To achieve the customer\’s requirements, which feature should be added?
A. Cisco MultiWay
B. Cisco TelePresence Conductor
C. Cisco TMS
D. Cisco Multisite
E. Cisco VCS Expressway
210-065 dump Correct Answer: D

A customer reports that in a CTS1300 room, a microphone switches to a segment that has no one talking. Which step is first in the troubleshooting process?
A. Replace the microphones to stop phantom switching.
B. Reseat the microphone cables.
C. Recalibrate the microphones.
D. Reboot the codec.
E. Replace the audio expansion box because the microphones connect to an AV expansion box.
Correct Answer: C

Which codec represents video that is supported by Cisco TelePresence endpoints?
A. H.263
B. H.323
C. H.264
D. H.262
210-065 pdf Correct Answer: C

Which CLI command must be used to configure the network settings on a Cisco TelePresence 4500 MCU?
A. Static A andlt;IP addressandgt; andlt;netmaskandgt; [andlt;default gateway addressandgt;]
B. Network ipandlt;ip addressandgt;andlt;netmaskandgt;andlt;default gatewayandgt;andlt;DNS server addressandgt;
C. Xconfig network addressandlt;ip addressandgt;andlt;netmaskandgt;andlt;default gatewayandgt;
D. Xconfig network addressandlt;ip addressandgt;andlt;netmaskandgt;andlt;default gatewayandgt;andlt;DNS server addressandgt;
Correct Answer: A

Which three of these are valid ways to initially configure a C-Series codec in a network where DHCP is not used? (Choose three.)
A. Tandberg Remote Control V
B. secure copy program
C. CLI using a console cable
D. touchscreen interface
E. secure web browser
F. Telnet
210-065 vce Correct Answer: ACD

A Cisco engineer needs to provide digital media for the lobby of a company. Which Cisco Digital Media component should the engineer use?
A. Cisco Cast
B. Cisco Digital Signs
C. Cisco DMP

D. Cisco Show and Share
E. Cisco IP TV
Correct Answer: B

An end user is in Cisco TelePresence session with a remote participant and can control the camera at the remote endpoint. Which feature is underlying in this scenario?
210-065 exam Correct Answer: C

Threat monitoring in physical access security can be based upon which three of these? (Choose three.)
A. doors
B. badges
C. age
D. weather
E. height
F. fingerprints
Correct Answer: ABF

Which CLI command can be used to reset the Cisco TelePresence System 500-32 personal video system to a factory condition?
A. utils factory reset 2
B. utils system factory init
C. xcommand defaultvalues set level: 2
D. xconfiguration default factory
E. utils reset factory
F. xcommand SystemUnit FactoryReset
210-065 dump Correct Answer: B

When you register the Cisco TelePresence System 500-32 video system with the Cisco Unified Communications Manager, what is the most important item for the registration to be input into the server?
A. the IPv4 address of the Cisco TelePresence System 500-32
B. the IP telephone media access control address that is used to manage the system
C. the media access control address of the Ethernet port of the Cisco TelePresence System 500-32
D. The Cisco TelePresence System 500-32 will always automatically register with the Cisco Unified Communications Manager server.
Correct Answer: C

Which three features does Cisco VCS provide? (Choose three.)
A. native Cisco SCCP telephony integration
B. SIP-H.323 interworking functionality
C. native scheduling
D. SIP trunk integration with Cisco Unified Communications Manager
E. third-party standards-based H.323 and SIP device registration
F. reverse proxy functionality
210-065 pdf Correct Answer: BDE

When connecting to a pan-tilt-zoom camera to a C-Series codec, what type of cable must be used for camera control?
A. an Ethernet crossover cable (RJ45-to-RJ45)
B. an Ethernet cable (RJ45-to-RJ45)
C. a serial cable (DB25-to-DB9)
D. a VISCA cable (DB9-to-RJ45)
Correct Answer: D

Refer to the exhibit.
An H.323 endpoint that is registered to Cisco VCS Control is not able to make B2B calls. Calls to other internal endpoints are working fine. What is the likely cause of the issue?
A. The Conductor H.323 zone is set to andquot;Off.andquot;
B. The Traversal Zone H.323 zone is set to andquot;Off.andquot;
C. The Production CUCM H.323 zone is set to andquot;Off.andquot;
D. The Traversal Zone H.323 zone is in a andquot;Failedandquot; state.
210-065 vce Correct Answer: B

Which of the following Nmap commands would be used to perform a UDP scan of the lower 1024 ports?
A. Nmap -h -U
B. Nmap -hU <host(s.>
C. Nmap -sU -p 1-1024 <host(s.>
D. Nmap -u -v -w2 <host> 1-1024
E. Nmap -sS -O target/1024
Correct Answer: C
Nmap -sU -p 1-1024 <hosts.> is the proper syntax. Learning Nmap and its switches are critical for successful completion of the CEH exam.

While reviewing the result of scanning run against a target network you come across the following: Which among the following can be used to get this output?
A. A Bo2k system query.
B. nmap protocol scan
C. A sniffer
D. An SNMP walk
210-065 exam 
Correct Answer: D
SNMP lets you “read” information from a device. You make a query of the server (generally known as the “agent”). The agent gathers the information from the host system and returns the answer to your SNMP client. It’s like having a single interface for all your informative Unix commands. Output like system.sysContact.0 is called a MIB.

You are manually conducting Idle Scanning using Hping2. During your scanning you notice that almost every query increments the IPID regardless of the port being queried. One or two of the queries cause the IPID to increment by more than one value. Why do you think this occurs?
A. The zombie you are using is not truly idle.
B. A stateful inspection firewall is resetting your queries.
C. Hping2 cannot be used for idle scanning.
D. These ports are actually open on the target system.
Correct Answer: A
If the IPID is incremented by more than the normal increment for this type of system it means that the system is interacting with some other system beside yours and has sent packets to an unknown host between the packets destined for you.

While performing ping scans into a target network you get a frantic call from the organization’s security team. They report that they are under a denial of service attack. When you stop your scan, the smurf attack event stops showing up on the organization’s IDS monitor. How can you modify your scan to prevent triggering this event in the IDS?
A. Scan more slowly.
B. Do not scan the broadcast IP.
C. Spoof the source IP address.
D. Only scan the Windows systems.
210-065 dump 
Correct Answer: B
Scanning the broadcast address makes the scan target all IP addresses on that subnet at the same time.

You are concerned that someone running PortSentry could block your scans, and you decide to slow your scans so that no one detects them. Which of the following commands will help you achieve this?
A. nmap -sS -PT -PI -O -T1 <ip address>
B. nmap -sO -PT -O -C5 <ip address>
C. nmap -sF -PT -PI -O <ip address>
D. nmap -sF -P0 -O <ip address>
Correct Answer: A
-T[0-5]: Set timing template (higher is faster)

You are performing a port scan with nmap. You are in hurry and conducting the scans at the fastest possible speed. However, you don’t want to sacrifice reliability for speed. If stealth is not an issue, what type of scan should you run to get very reliable results?
A. XMAS scan
B. Stealth scan
C. Connect scan

D. Fragmented packet scan
210-065 pdf 
Correct Answer: C
A TCP Connect scan, named after the Unix connect() system call is the most accurate scanning method. If a port is open the operating system completes the TCP three-way handshake, and the port scanner immediately closes the connection.

Neil notices that a single address is generating traffic from its port 500 to port 500 of several other machines on the network. This scan is eating up most of the network bandwidth and Neil is concerned. As a security professional, what would you infer from this scan?
A. It is a network fault and the originating machine is in a network loop
B. It is a worm that is malfunctioning or hardcoded to scan on port 500
C. The attacker is trying to detect machines on the network which have SSL enabled
D. The attacker is trying to determine the type of VPN implementation and checking for IPSec
Correct Answer: D
Port 500 is used by IKE (Internet Key Exchange). This is typically used for IPSEC-based VPN software, such as Freeswan, PGPnet, and various vendors of in-a box VPN solutions such as Cisco. IKE is used to set up the session keys. The actual session is usually sent with ESP (Encapsulated Security Payload) packets, IP protocol 50 (but some in-a-box VPN’s such as Cisco are capable of negotiating to send the encrypted tunnel over a UDP channel, which is useful for use across firewalls that block IP protocols other than TCP or UDP).

