About the Exam

This proctored exam tests foundational skills in Network Access Control using the HPE Aruba Networking ClearPass product portfolio. It is part of the HPE Advanced Product Certified - ClearPass certification path and has no listed prerequisites. Passing demonstrates that the candidate understands the ClearPass concepts and configuration skills expected for that certification track.

Exam Topics

  • Identify Network Access Control and Security Features15%
  • Identify ClearPass Modules and System Components10%
  • Define Authentication, Authorization, and Accounting (AAA) and how they work10%
  • Identify Service Configuration and Selection in HPE Aruba Networking ClearPass15%
  • Define Guest Access Management and Captive Portal10%
  • Identify Dynamic User Roles and Segmentation15%
  • Define Onboard Provisioning and Posture Attribute Enforcement10%
  • Define ClearPass Server Management and Administration15%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated April 5, 2026 at 7:25 PM

Topic filter
Retired questions
Question sort
Questions per page

QuestionQ1

Define Onboard Provisioning and Posture Attribute Enforcement

A network administrator must revoke a certificate for a lost device so it can no longer access the network. They go to the Certificate Authorities section in ClearPass Onboard.

What should they do next to ensure the certificate is correctly revoked and the device is blocked?

Explanation

A Certificate Authority’s Certificates action displays the certificates associated with that CA, allowing the administrator to locate and revoke the specific client certificate issued to the lost device. Certificate revocation makes the certificate invalid for subsequent CRL or OCSP validity checks and prevents certificate-based authentication.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

Define Guest Access Management and Captive Portal

A network engineer is diagnosing an issue in which a factory-default Aruba Network device is not correctly redirecting DNS requests. The device should intercept requests for ‘securelogin.hpe.com’ but is not doing so.

What is a likely cause of this problem?

Explanation

Aruba’s default captive-portal certificate uses securelogin.hpe.com as its common name. The captive-portal address must match the certificate’s common name; if the certificate common name differs, requests for securelogin.hpe.com will not align with the configured portal identity and interception/redirection can fail.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Define Authentication, Authorization, and Accounting (AAA) and how they work

A network administrator is configuring ClearPass for a large organization and must ensure that user credentials are validated efficiently while also collecting rich context about the users.

Which authentication source should the administrator prioritize to meet this need?

Explanation

Active Directory is an enterprise identity repository that lets ClearPass validate user credentials and retrieve directory attributes for authorization and role mapping, providing rich user context such as group membership and other user properties.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

Define Guest Access Management and Captive Portal

After a guest user submits a self-registration form, their account is created in a disabled state. What visual indication on the registration receipt shows this status?

Explanation

A disabled guest account is not eligible to authenticate, so the registration receipt renders the Log In control inactive (grayed out) until the account is enabled or approved.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

Define Guest Access Management and Captive Portal

An organization is configuring a guest network with ClearPass and wants to provide a seamless login experience for returning visitors.

Which approach should it use to meet this goal while retaining a reasonable level of security?

Explanation

Combining MAC authentication with captive-portal authentication lets a guest complete the portal flow initially and associates the device MAC address with the guest access record. Subsequent connections can be recognized through MAC authentication for the valid access period, while the captive portal still provides controlled guest onboarding and account-expiration policies.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!
Know a question that should be here? Contribute to this exam
Back home