About the Exam

This proctored exam is for network security professionals working with HPE Aruba Networking solutions. It covers intermediate network security concepts including firewall, proxy, remote access, IDS/IPS, access control, NTA, UEBA, device hardening, and Zero Trust Security. Passing demonstrates that you can understand and explain the network security stack and related Aruba security implementation concepts.

Exam Topics

  • Define security terminology26%
  • Device hardening6%
  • Secure WLAN12%
  • Secure wired AOS-CX19%
  • Secure the WAN5%
  • Endpoint classification16%
  • Threat detection9%
  • Troubleshooting6%
  • Forensics1%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated January 4, 2026 at 7:56 PM

Topic filter
Retired questions
Question sort
Questions per page

QuestionQ1

Secure wired AOS-CX

An AOS-CX switch running AOS 10.07 has the following configuration:

class ip all  
10 match any any any  
class ipv6 all  
10 match any any any  
port-access policy policy1  
10 class ip all action drop  
20 class ipv6 all action drop  
port-access role role1  
associate policy policy1  
port-access role role2  
vlan access 19 $  

The company wants to place clients whose authentication times out—either at the client end or because the RADIUS server does not respond—into VLAN 19. The company wants to continue denying access to clients that fail authentication.

Which roles should be configured on edge ports?

Explanation

In AOS-CX, the fallback role applies when an 802.1X supplicant times out, while the critical role applies when RADIUS is unreachable or the RADIUS request times out. Both must be role2 to assign VLAN 19. The reject role applies when authentication fails; it must be role1 because policy1 drops all IPv4 and IPv6 traffic, preserving denial of access.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

Secure wired AOS-CX

A company uses HPE Aruba Networking APs and AOS-CX switches. The APs bridge wireless traffic and obtain DHCP IP addresses on VLAN 18. Wireless users are placed on VLAN 12. The company plans to begin using 802.1X authentication for the APs.

You are configuring the port-access role assigned to the APs after authentication. What is one recommended setting for this role?

Explanation

An AP that bridges wireless client traffic should be treated as a trusted infrastructure device and allowed to preserve DSCP markings so QoS classification can be maintained for traffic traversing the AP. AOS-CX port-access roles support trust-mode dscp, which explicitly trusts DSCP values while retaining 802.1p priority.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Threat detection

A company uses HPE Aruba Networking gateways that implement gateway IDS/IPS. Administrators occasionally review the Security Dashboard, but they want a quicker way to learn when a gateway begins detecting threats in traffic.

What should they do?

Explanation

HPE Aruba Networking Central can generate Gateway IDS/IPS threat alerts when configured threat-count thresholds are exceeded and send those alerts by email to configured recipients. Global alert settings are therefore the direct way to proactively notify administrators of detected threats.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

Secure WLAN

Your company intends to implement Tunneled EAP (TEAP).

How can you configure HPE Aruba Networking ClearPass Policy Manager (CPPM) to enforce certificate-based authentication for clients that use TEAP?

Explanation

TEAP supports tunneled inner methods, including EAP-TLS. EAP-TLS performs mutual certificate-based authentication, so selecting an EAP-TLS-type method as the TEAP inner method requires clients to authenticate with certificates. A server/service certificate establishes and validates the outer TLS tunnel but does not, by itself, enforce client-certificate authentication.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

Endpoint classification

A company uses both HPE Aruba Networking ClearPass Manager (CPPM) and HPE Aruba Networking ClearPass Device Insight (CPDI).

What is one way that integration between the two solutions can help the company implement Zero Trust Security?

Explanation

CPDI can tag classified endpoints based on observed criteria, and those tags are sent to CPPM as endpoint attributes. CPPM can use the tags in role-mapping and enforcement policies, allowing it to direct the network infrastructure to quarantine endpoints associated with prohibited application use or other risky behavior.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!
Know a question that should be here? Contribute to this exam
Back home