No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Refer to the exhibit.
Based on the information shown, what is the purpose of using [Time Source] for authorization?
Ato check how long it has been since the last login authentication
Bto check whether the guest account expired
Cto check whether the MAC address is in the MAC Caching repository
Dto check whether the MAC address status is known in the endpoints table
Eto check whether the MAC address status is unknown in the endpoints table
An organization has chosen to implement dual-SSID Onboarding. An administrator used the Onboard service template to create services for dual-SSID Onboarding.
Which statement is correct?
AThe Onboard Authorization service is triggered when the user connects to the secure SSID.
BThe Onboard Authorization service is triggered during the Onboarding process.
CThe Onboard Authorization service is never triggered.
DThe device connects to the secure SSID for provisioning.
EThe Onboard Provisioning service is triggered when the user connects to the provisioning SSID to Onboard their device.
An Android device completes the single-SSID Onboarding process and successfully connects to the secure network with EAP-TLS.
An Enforcement Profile has been configured in Policy Manager as shown. Which action will ClearPass perform based on this Enforcement Profile?
AClearPass will count down 600 seconds and send a RADIUS CoA message to the user to end the user's session after this time is up.
BClearPass will send the Session-Timeout attribute in the RADIUS Access-Accept packet to the NAD and the NAD will end the user's session after 600 seconds.
CClearPass will count down 600 seconds and send a RADIUS CoA message to the NAD to end the user's session after this time is up.
DClearPass will send the Session-Timeout attribute in the RADIUS Access-Request packet to the NAD and the NAD will end the user's session after 600 seconds.
EClearPass will send the Session-Timeout attribute in the RADIUS Access-Accept packet to the User and the user's session will be terminated after 600 seconds.
A bank wants to deploy ClearPass Guest with web-login authentication so its customers can self-register on the network and obtain network access when meeting with bank employees. However, the bank has security concerns.
Which statements are true?
Choose three
AIf HTTPS is used for the web login page, after authentication is completed guest Internet traffic will all be encrypted as well.
BDuring web login authentication, if HTTPS is used for the web login page, guest credentials will be encrypted.
CAfter authentication, an IPSEC VPN on the guest's client be used to encrypt Internet traffic.
DHTTPS should never be used for Web Login Page authentication.
EIf HTTPS is used for the web login page, after authentication is completed some guest Internet traffic may be unencrypted.
What does the QUARANTINE Posture Token indicate?
AThe client is compliant. However, there is an update available to remediate the client to HEALTHY state.
BThe posture of the client is unknown.
CThe client is infected and is a threat to other systems in the network.
DThe client is out of compliance, but has HEALTHY state.
EThe client is out of compliance.
A customer wants to make enforcement decisions during 802.1X authentication according to a client’s OnGuard posture token.
Which enforcement profile should be used in the health check service?
AQuarantine VLAN
BRADIUS CoA
CRADIUS Accept
DRADIUS Reject
EFull Access VLAN.
Refer to the exhibit.
A user has logged in to the Self-Service Portal as shown. What do the traffic-received and traffic-sent statistics represent?
AThese show the total amount of traffic the guest transmitted, as seen through RADIUS CoA packets from the NAD to ClearPass.
BThese show the total amount of traffic the NAD transmitted to ClearPass, as seen through RADIUS accounting messages from the NAD to ClearPass.
CThese show the total amount of traffic the guest transmitted after account expiration, as seen through RADIUS accounting messages sent from the NAD to ClearPass.
DThese show the total amount of traffic the guest transmitted, as seen through RADIUS CoA packets from the client to ClearPass.
EThese show the total amount of traffic the guest transmitted, as seen through RADIUS accounting messages sent from the NAD to ClearPass.
Refer to the exhibit.
A user tagged with the ClearPass roles Role_Engineer and developer, but not testqa, connects to the network using a corporate Windows laptop. Which Enforcement Profile is applied?
AWIRELESS_GUEST_NETWORK
BWIRELESS_CAPTIVE_NETWORK
CWIRELESS_HANDHELD_NETWORK
DWIRELESS_EMPLOYEE_NETWORK
Which statements are true about configuring a generic LDAP server as an External Authentication server in ClearPass?
Choose three
AGeneric LDAP Browser can be used to search the Base DN.
BAn administrator can customize the selection of attributes fetched from an LDAP server.
CThe bind DN can be in the administrator@domain format.
DA maximum of one generic LDAP server can be configured in ClearPass.
EA LDAP Browser can be used to search the Base DN.
Which authorization servers does ClearPass support?
Choose two
AActive Directory
BCisco Controller
CAruba Controller
DLDAP server
EAruba Mobility Access Switch
Refer to the exhibit.
Based on the Enforcement Policy configuration, when a user with the Engineer role connects to the network and is assigned an Unknown posture token, which Enforcement Profile is applied?
ARestrictedACL
BHR VLAN
CRemote Employee ACL
D[Deny Access Profile]
EEMPLOYEE_VLAN
Refer to the exhibit.
When configuring a Web Login Page in ClearPass Guest, the displayed information is shown. What is the Page Name field used for?
AFor Administrators to access the PHP page, but not guests.
BFor forming the Web Login Page URL.
CFor forming the Web Login Page URL where Administrators add guest users.
DFor Administrators to reference the page only.
EFor forming the Web Login Page URL and the page name that guests must configure on their laptop wireless supplicant.
Refer to the exhibit.
What is the purpose of the “Clock Skew Allowance” setting?
Choose two
Ato ensure server certificate validation does not fail due to client clock sync issues
Bto set expiry time in client certificate to a few minutes longer that the default setting
Cto adjust clock time on client device to a few minutes before current time
Dto ensure client certificate validation does not fail due to client clock sync issues
Eto set start time in client certificate to a few minutes before current time
Which components can use Active Directory authorization attributes in the decision-making process?
Choose two
APosture policy
BRole Mapping policy
CCertificate validation policy
DProfiling policy
EEnforcement policy
In single-SSID Onboarding, which method can be used in the Enforcement Policy to differentiate a provisioned device from a device that has not completed the Onboard workflow?
AOnguard Agent used
BAuthentication Method used
CNetwork Access Device used
DActive Directory Attributes
EEndpoint OS Category
Refer to the exhibit.
Based on the displayed Attribute configuration, which statement correctly describes the status of the attribute values?
AThe attribute values of department, title, memberOf, telephoneNumber, mail are directly applied as ClearPass roles.
BThe attribute values of department and memberOf are directly applied as ClearPass roles.
COnly the attribute value of company can be used in role mapping policies, not other attributes.
DOnly the attribute value of department and memberOf can be used in role mapping policies.
EOnly the attribute value of title, memberOf, telephoneNumber can be used in role mapping policies.
Refer to the exhibit below.
Based on the policy configuration shown, which VLAN is assigned when a user with the ClearPass role Engineer successfully authenticates to the network on Saturday using the WEBAUTH connection protocol?
AFull Access VLAN
BDeny Access
CEmployee Vlan
DInternet VLAN
What does Authorization enable us to do in a Policy Service?
ATo use attributes in databases in role mapping and Enforcement.
BTo use attributes stored in databases in Enforcement only, but not role mapping.
CTo use attributes stored in external databases for Enforcement, but not internal databases.
DTo use attributes stored in databases in role mapping only, but not Enforcement.
ETo use attributes sored in internal databases for Enforcement, but not external databases.
A University plans to deploy ClearPass with the Guest module. Two types of users need web-login authentication. The first type is students whose accounts are in an Active Directory server. The second type is friends of students who must self-register for network access.
How should the service be configured in Policy Manager for this network?
AEither the Guest User Repository or Active Directory server should be the single authentication source.
BGuest User Repository as the authentication source, and Guest User Repository and Active Directory server as authentication sources.
CGuest User Repository as the authentication source and the Active Directory server as authentication source.
DActive Directory server as authentication source and the Guest User Repository as the authentication source.
EGuest User Repository and Active Directory server both as authentication sources.
Community Discussion