A company is deploying AOS-CX switches to support 722 employees. The switches will tunnel client traffic to an HPE Aruba Networking Mobility Controller (MC), allowing the MC to apply firewall policies and deep packet inspection (DPI). This MC will be dedicated to receiving traffic from the AOS-CX switches.
What licensing does the MC require?
Aone PEF license per-switch
Bone AP license per-switch
Cone PEF license per-switch, and one WCC license per-switch
Done AP license per-switch, and one PEF license per-switch
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ2
Protect and Defend
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ3
Investigate
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ4
Protect and Defend
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ5
Analyze
0
Community Discussion
No comments yet. Be the first to start the discussion!
You have an HPE Aruba Networking Mobility Controller (MC) that is secured in a locked closet.
What additional step does HPE Aruba Networking recommend to protect the MC against unauthorized access?
AChange the password recovery password.
BDisable local authentication of administrators entirely.
CSet the local admin password to a long random value that is unknown or locked up securely.
DUse local authentication rather than external authentication to authenticate admins.
Refer to the exhibit.
You are deploying a new HPE Aruba Networking Mobility Controller (MC) that enforces authentication through HPE Aruba Networking ClearPass Policy Manager (CPPM). Authentication is not functioning correctly, and the CPPM Event Viewer displays the error shown in the exhibit.
What should you verify?
Athat the MC has been added as a domain machine on the Active Directory domain with which CPPM is synchronized
Bthat the MC has valid admin credentials configured on it for logging into the CPPM
Cthat the IP address that the MC is using to reach CPPM matches the one defined for the device on CPPM
Dthat the shared secret configured for the CPPM authentication server matches the one defined for the device on CPPM
You are deploying an HPE Aruba Networking mobility solution for a university that includes a Mobility Master (MM), Mobility Controllers (MCs), and campus APs (CAPs). The university plans to enforce WPA2-Enterprise for every user connection. It wants to apply one set of access-control rules to faculty users’ traffic and a separate set of rules to students’ traffic.
What is the best approach for applying the appropriate rules to each group?
ACreate two roles, a "faculty" role and a "student" role. Apply firewall policies with the correct rules for each group to each role.
BCreate two VLANs, one for faculty and one for students. Create one set of firewall access control rules that specify faculty IP addresses for the source and a second set of rules that specify the student IP addresses for the source. Apply the rules to the WLAN.
CCreate two VLANs, one for faculty and one for students. Apply firewall policies with the correct rules for each group to each VLAN.
DCreate two WLANs, one for faculty and one for students. Apply firewall policies with the correct rules for each group to each WLAN.
What is one way HPE Aruba Networking ClearPass Policy Manager (CPPM) can use DHCP to classify an endpoint?
AIt can alter the DHCP Offer to insert itself as a proxy gateway. It will then be inline in the traffic flow and can apply traffic analytics to classify clients.
BIt can snoop DHCP traffic to register the clients’ IP addresses. It then knows where to direct its HTTP requests to actively probe for information about the client.
CIt can respond to a client’s DHCP Discover with different DHCP Offers and then analyze the responses to identify the client OS.
DIt can determine information such as the endpoint OS from the order of options listed in Option 55 of a DHCP Discover packet.
QuestionQ6
Analyze
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ7
Analyze
QuestionQ8
Analyze
QuestionQ9
Analyze
QuestionQ10
Investigate
QuestionQ11
Investigate
QuestionQ12
Protect and Defend
QuestionQ13
Analyze
QuestionQ14
Analyze
QuestionQ15
Analyze
QuestionQ16
Protect and Defend
QuestionQ17
Investigate
QuestionQ18
Analyze
QuestionQ19
Analyze
QuestionQ20
Analyze
QuestionQ21
Analyze
QuestionQ22
Protect and Defend
QuestionQ23
Analyze
QuestionQ24
Analyze
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
What is one advantage of Opportunistic Wireless Encryption (OWE)?
AIt allows anyone to connect, but provides better protection against eavesdropping than a traditional open network.
BIt offers more control over who can connect to the wireless network when compared with WPA2-Personal.
CIt allows both WPA2-capable and WPA3-capable clients to authenticate to the same WPA-Personal WLAN.
DIt provides protection for wireless clients against both honeypot APs and man-in-the-middle (MITM) attacks.
Refer to the exhibit.
The exhibit shows the configuration on an AOS-CX switch. Client1 connects to port 1/1/1 and authenticates with HPE Aruba Networking ClearPass Policy Manager (CPPM). CPPM returns an Access-Accept with this VSA: Aruba-User-Role: role4.
Client2 connects to port 1/1/2 and does not attempt authentication. To which roles are the users assigned?
AClient1 = role3; Client2 = role2
BClient1 = role4; Client2 = role2
CClient1 = role4; Client2 = role1
DClient1 = role3; Client2 = role1
Refer to the exhibit, which displays the settings on the company’s MCs.
You have deployed about 100 new HPE Aruba Networking 335 APs. What is required for the APs to become managed?
Aapproving the APs as authorized APs on the AP whitelist
Binstalling self-signed certificates on the Aps
Cconfiguring a PAPI key that matches on the APs and MCs
Dinstalling CA-signed certificates on the Aps
Refer to the exhibits.
An administrator has created a WLAN using the settings shown in the exhibits and has made no other changes to the AAA profile. A client connects to the WLAN.
Under what circumstances will the client receive the default role assignment?
AThe client has passed 802.1 X authentication, and the authentication server did not send an Aruba-User-Role VSA.
BThe client has passed 802.1X authentication, and the value in the Aruba-User-Role VSA matches a role on the MC.
CThe client has attempted 802.1 X authentication, but the MC could not contact the authentication server.
DThe client has attempted 802.1 X authentication, but failed to maintain a reliable connection, leading to a timeout error.
You need to locate port-authentication logs on an AOS-CX switch for events recorded during the last several hours, but searching the logs is difficult.
What is one method you can use to locate the relevant logs?
AEnable debugging for "portaccess" to move the relevant logs to a buffer.
BSpecify a logging facility that selects for "port-access" messages.
CAdd the "-r" and "-c port-access" options to the "show logging" command.
DConfigure a logging filter for the "port-access" category, and apply that filter globally.
A company has HPE Aruba Networking Mobility Controllers (MCs), campus APs, and AOS-CX switches. It plans to use HPE Aruba Networking ClearPass Policy Manager (CPPM) to classify endpoints by type. The HPE Aruba Networking ClearPass administrators want to run Network scans as part of the solution.
What should you configure in the infrastructure to support the scans?
ACreate remote mirrors on the AOS-CX switches that collect traffic on edge ports, and mirror it to CPPM’s IP address.
BCreate device fingerprinting profiles on the AOS-CX switches that include SNMP, and apply the profiles to edge ports.
CCreate SNMPv3 users on the AOS-CX switches, and make sure that the credentials match those configured on CPPM.
DCreate a TA profile on the AOS-CX switches with the root CA certificate for HPE Aruba Networking ClearPass’s HTTPS certificate.
What is one advantage of deploying HPE Aruba Networking ClearPass Device Insight?
AVisibility into devices’ 802.1X supplicant settings and automated certificate deployment
BAgent-based analysis of devices’ security settings and health status, with the ability to implement quarantining
CSimpler troubleshooting of ClearPass solutions across an environment with multiple ClearPass Policy Managers
DHighly accurate endpoint classification for environments with many devices types, including Internet of Things (IoT)
A client is connected to a Mobility Controller (MC). The following firewall rules apply to the client’s role:
ipv4 any any svc-dhcp permit
ipv4 user 10.1.5.20 svc-dns permit
ipv4 user 10.1.1.0 255.255.255.0 https permit
ipv4 user 10.1.0.0 255.255.0.0 https deny_opt
ipv4 user any any permit
What correctly describes the controller’s treatment of HTTPS packets to these two IP addresses, both located on the other side of the firewall?
10.1.20.1
10.1.5.20
ABoth packets are permitted.
BBoth packets are denied.
CThe first packet is denied, and the second is permitted.
DThe first packet is permitted, and the second is denied.
A customer operates an HPE Aruba Networking network infrastructure and is seeking a solution that can classify numerous device types, including IoT devices.
What can you offer?
AHPE Aruba Networking ClearPass OnGuard
BHPE Aruba Networking ClearPass Device Insight
CHPE Aruba Networking Mobility Conductor
DHPE Aruba Networking ClearPass Onboard
Which statement accurately describes a type of malware?
AA Trojan is any type of malware that replicates itself and spreads to other systems automatically.
BMalvertising can only infect a system if the user encounters the malware on an untrustworthy site.
CWorms are usually delivered in spear-phishing attacks and require users to open and run a file.
DRootkits can help hackers gain elevated access to a system and often actively conceal themselves from detection.
Which scenario requires an AOS-CX switch to use its own certificate?
Aenabling the switch to use RADIUS for enforcing 802.1X authentication with PEAP
Benabling the switch to use RadSec for enforcing 802.1X authentication with EAP-TLS
Cenabling the switch to use RADIUS for enforcing 802.1X authentication with EAP-TLS
Denabling the switch to retrieve Downloadable User Roles (DURs) from HPE Aruba Networking ClearPass
You have deployed a new HPE Aruba Networking Mobility Controller (MC) and campus APs (CAPs). One WLAN requires 802.1X authentication through HPE Aruba Networking ClearPass Policy Manager (CPPM). When you test a client connection to the WLAN, the test fails. You check ClearPass Access Tracker but find no record of the authentication attempt. A ping from the MC to CPPM succeeds.
What is a suitable next troubleshooting step?
ACheck connectivity between CPPM and a backend directory server.
BCheck CPPM Event Viewer.
CRenew CPPM’s RADIUS/EAP certificate.
DReset the user credentials.
What is one way in which WPA3-Personal improves security compared with WPA2-Personal?
AWPA3-Personal is more resistant to passphrase cracking because it requires passphrases to be at least 12 characters.
BWPA3-Personal is more secure against password leaking because all users have their own username and password.
CWPA3-Personal prevents eavesdropping on other users' wireless traffic by a user who knows the passphrase for the WLAN.
DWPA3-Personal is more complicated to deploy because it requires a backend authentication server.
What is one use case for Transport Layer Security (TLS)?
Ato enable a client and a server to establish secure communications for another protocol
Bto enable two parties to asymmetrically encrypt and authenticate all data that passes between them
Cto establish a framework for devices to determine when to trust other devices’ certificates
Dto provide a secure alternative to certificate authentication that is easier to implement
An MC has a WLAN that enforces WPA3-Enterprise and authenticates with HPE Aruba Networking ClearPass Policy Manager (CPPM). The WLAN’s default role is configured as denyall. A Mobility Controller (MC) has these roles configured:
authenticated
denyall
guest
accounting
guest-logon
logon
stateful-dot1x
switch-logon
voice
A client authenticates, and CPPM returns an Access-Accept with the Aruba-User-Role VSA set to accountants. Which role does the client receive?
Aguest
Bauthenticated
Cdenyall
Dlogon
Your AOS solution has identified a rogue AP using Wireless Intrusion Prevention (WIP).
Which detected-radio information would best help you locate the rogue device?
Athe match type
Bthe match method
Cthe detecting devices
Dthe confidence level
Refer to the exhibit.
This company uses AOS-CX switches. The exhibit depicts one access-layer switch, Switch-2, as an example, although the campus contains additional switches.
The company wants to prevent internal users from exploiting ARP. Assume that DHCP snooping is already correctly configured in the environment.
What is the appropriate way to configure the switches to satisfy these requirements?
AOn Switch-2, set the interface that connects to Switch-1 as a trusted port for ARP inspection; enable ARP inspection on VLAN 201.
BOn Switch-2, make ports connected to employee devices trusted ports for ARP inspection; enable ARP inspection globally.
COn Switch-2, configure static IP-to-MAC bindings for all end-user devices on the network.
DOn Switch-1, enable ARP inspection on all VLANs; do not configure any interfaces as trusted ports for ARP inspection.
What distinguishes passive endpoint classification from active endpoint classification?
APassive classification analyzes traffic that endpoints send as part of their normal functions; active classification involves sending requests to endpoints.
BPassive classification is only suitable for profiling endpoints in small business environments, while enterprises should use active classification exclusively.
CPassive classification refers exclusively to MAC OUI-based classification, while active classification refers to any other classification method.
DPassive classification classifies endpoints based on entries in dictionaries, while active classification uses admin-defined rules to classify endpoints.
A client accessed an HTTPS server at myhost1.example.com by using Chrome. The server provides a certificate with these properties:
Subject name: myhost1.example.com
SAN: DNS: myhost.example.com
Extended Key Usage (EKU): Server authentication
Issuer: MyCA_Signing
The server also provides an intermediate CA certificate for MyCA_Signing, signed by MyCA. The client’s Trusted CA Certificate list contains MyCA, but not MyCA_Issuing.
Which factor or factors stop the client from trusting the certificate?
AThe certificate lacks a valid SAN.
BThe client does not have the correct trusted CA certificates.
CThe certificate lacks the correct EKU.
DThe certificate lacks a valid SAN, and the client does not have the correct trusted CA certificates.
Community Discussion