About the Exam

This proctored, 60-question, 90-minute exam is tied to the HPE Aruba Networking Certified Associate - Network Security certification. It validates knowledge of common security threats and vulnerabilities and an understanding of device hardening. Passing demonstrates foundational network security knowledge for HPE Aruba Networking environments.

Exam Topics

  • Protect and Defend70%
  • Analyze24%
  • Investigate6%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated March 17, 2026 at 1:44 AM

Topic filter
Retired questions
Question sort
Questions per page

QuestionQ1

Protect and Defend

A company is deploying AOS-CX switches to support 722 employees. The switches will tunnel client traffic to an HPE Aruba Networking Mobility Controller (MC), allowing the MC to apply firewall policies and deep packet inspection (DPI). This MC will be dedicated to receiving traffic from the AOS-CX switches.

What licensing does the MC require?

Explanation

For Dynamic Segmentation, each AOS-CX switch that tunnels traffic to a Mobility Controller consumes an AP license, because the controller treats the tunneling switch as an AP-equivalent device. Centralized firewall policy enforcement and DPI require a PEF license as well. License consumption is per switch or switch stack, rather than per client or employee.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

Protect and Defend

You have an HPE Aruba Networking Mobility Controller (MC) that is secured in a locked closet.

What additional step does HPE Aruba Networking recommend to protect the MC against unauthorized access?

Explanation

The local admin/root account should have a long, complex, randomly generated password that is securely stored and unavailable to ordinary users. This prevents misuse of the local administrative account while centralized TACACS or RADIUS authentication is used for normal administrative access.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Investigate

Refer to the exhibit.

Question Image

You are deploying a new HPE Aruba Networking Mobility Controller (MC) that enforces authentication through HPE Aruba Networking ClearPass Policy Manager (CPPM). Authentication is not functioning correctly, and the CPPM Event Viewer displays the error shown in the exhibit.

What should you verify?

Explanation

An “unknown NAD” RADIUS event means ClearPass cannot associate the incoming RADIUS request with a configured network access device. The Mobility Controller’s source IP address for traffic to ClearPass must therefore match the IP address configured for that device in ClearPass.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

Protect and Defend

You are deploying an HPE Aruba Networking mobility solution for a university that includes a Mobility Master (MM), Mobility Controllers (MCs), and campus APs (CAPs). The university plans to enforce WPA2-Enterprise for every user connection. It wants to apply one set of access-control rules to faculty users’ traffic and a separate set of rules to students’ traffic.

What is the best approach for applying the appropriate rules to each group?

Explanation

In ArubaOS, an authenticated client is assigned a user role that determines its network privileges, and one or more firewall policies can be associated with that role. Assigning distinct faculty and student roles enables the controller to enforce the appropriate traffic rules per authenticated user group, independent of VLAN or WLAN membership.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

Analyze

What is one way HPE Aruba Networking ClearPass Policy Manager (CPPM) can use DHCP to classify an endpoint?

Explanation

ClearPass Policy Manager can fingerprint an endpoint from DHCP Discover and Request attributes, including the ordered parameter-request list in DHCP Option 55. That fingerprint can identify characteristics such as the device category, OS family, and device name.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

That's the end of the preview

It's free

100% of the questions are free for all users.
No strings attached.

Topics covered
Protect and DefendAnalyzeInvestigate
Know a question that should be here? Contribute to this exam
Back home