Aruba Certified Network Security Professional (HPE7-A02)Demo
By HP · Browse Mode
//
Aruba Certified Network Security Professional (HPE… Practice Exam
QuestionQ1
Secure wired AOS-CX
Save question
An AOS-CX switch running AOS 10.07 has the following configuration:
class ip all
10 match any any any
class ipv6 all
10 match any any any
port-access policy policy1
10 class ip all action drop
20 class ipv6 all action drop
port-access role role1
associate policy policy1
port-access role role2
vlan access 19 $
The company wants to place clients whose authentication times out—either at the client end or because the RADIUS server does not respond—into VLAN 19. The company wants to continue denying access to clients that fail authentication.
Which roles should be configured on edge ports?
ACritical role = role2; fallback role = role2; no reject role configured
BCritical role = role2; fallback role = role2; reject role = role1
CCritical role = role1; fallback role = role2; reject role = role1
DFallback role = role2; reject role = role1; no critical role configured
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ2
Secure wired AOS-CX
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ3
Threat detection
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ4
Secure WLAN
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ5
Endpoint classification
0
Community Discussion
No comments yet. Be the first to start the discussion!
It's free
100% of the questions are free for all users. No strings attached.
A company uses HPE Aruba Networking APs and AOS-CX switches. The APs bridge wireless traffic and obtain DHCP IP addresses on VLAN 18. Wireless users are placed on VLAN 12. The company plans to begin using 802.1X authentication for the APs.
You are configuring the port-access role assigned to the APs after authentication. What is one recommended setting for this role?
ATrust for DSCP
BAccess VLAN 18 with no support for VLAN 12
CAuth-mode left at client-mode
DNo trust for DSCP
A company uses HPE Aruba Networking gateways that implement gateway IDS/IPS. Administrators occasionally review the Security Dashboard, but they want a quicker way to learn when a gateway begins detecting threats in traffic.
What should they do?
ASet up Webhooks that are attached to the HPE Aruba Networking Central Threat Dashboard.
BUse Syslog to integrate the gateways with HPE Aruba Networking ClearPass Policy manager (CPPM) event processing.
CSet up email notifications using HPE Aruba Networking Central’s global alert settings.
DIntegrate HPE Aruba Networking ClearPass Device Insight (CPDI) with Central and schedule hourly reports.
Your company intends to implement Tunneled EAP (TEAP).
How can you configure HPE Aruba Networking ClearPass Policy Manager (CPPM) to enforce certificate-based authentication for clients that use TEAP?
ASelect a service certificate when you specify TEAP as a service’s authentication method.
BFor the service using TEAP, set the authentication source to an internal database.
CSelect an EAP-TLS-type authentication method for the TEAP method's inner method.
DCreate an authentication method named "TEAP" with the type set to EAP-TLS.
A company uses both HPE Aruba Networking ClearPass Manager (CPPM) and HPE Aruba Networking ClearPass Device Insight (CPDI).
What is one way that integration between the two solutions can help the company implement Zero Trust Security?
ACPPM can inform CPDI that it has assigned a particular Aruba-User-Role to a client, CPDI can then use that information to reclassify the client.
BCPDI can use tags to inform CPPM that clients are using prohibited applications; CPPM can then tell the network infrastructure to quarantine those clients.
CCPPM can provide CPDI with custom device fingerprint definitions in order to enhance the company’s total visibility.
DCPDI can provide CPPM with extra information about user’s identity; CPPM can then use that information to apply the correct identify-based enforcement.
QuestionQ6
Secure WLAN
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ7
Troubleshooting
QuestionQ8
Secure wired AOS-CX
QuestionQ9
Secure wired AOS-CX
QuestionQ10
Endpoint classification
QuestionQ11
Secure wired AOS-CX
QuestionQ12
Threat detection
QuestionQ13
Threat detection
QuestionQ14
Secure the WAN
QuestionQ15
Endpoint classification
QuestionQ16
Threat detection
QuestionQ17
Endpoint classification
QuestionQ18
Secure WLAN
QuestionQ19
Secure wired AOS-CX
QuestionQ20
Threat detection
QuestionQ21
Secure WLAN
QuestionQ22
Threat detection
QuestionQ23
Secure wired AOS-CX
QuestionQ24
Threat detection
QuestionQ25
Threat detection
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
A company uses HPE Aruba Networking APs (AOS-10) that authenticate clients through HPE Aruba Networking ClearPass Policy Manager (CPPM). CPPM is configured to receive various client-profile and posture details. New details might require CPPM to change a client’s enforcement profile.
What should be configured on the APs to help the solution work properly?
AIn the WLAN profiles, enable interim RADIUS accounting.
BIn the RADIUS server settings for CPPM, enable Dynamic Authorization.
CIn the RADIUS server settings for CPPM, enable querying the authentication status.
DIn the security settings, configure dynamic denylisting.
A ClearPass Policy Manager (CPPM) service has the following settings:
Role mapping policy:
Evaluate: Select first
Rule 1 conditions: Authorization:AD:Groups EQUALS Managers AND Authentication:TEAP-Method-1-Status EQUALS Success
Rule 1 conditions: Tips Role EQUALS manager AND Tips Role EQUALS domain-comp
Rule 1 profile list: domain-manager
Rule 2 conditions: Tips Role EQUALS manager
Rule 2 profile list: manager-only
Rule 3 conditions: Tips Role EQUALS domain-comp
Rule 3 profile list: domain-only
Default profile: [Deny access]
A client authenticates through the service. CPPM collects attributes showing that the user belongs to the Contractors group, and the client successfully passed both TEAP methods.
Which enforcement policy is applied?
A[Deny Access Profile]
Bmanager-only
Cdomain-manager
Ddomain-only
Refer to the exhibit.
The exhibit displays the TACACS+ enforcement profile that HPE Aruba Networking ClearPass Policy Manager (CPPM) assigns to a manager. When this manager logs in to an AOS-CX switch, what does the switch do?
AAssigns the manager operator-level privileges
BAssigns the manager administrator-level privileges
CRejects the manager with an error message
DAssigns the manager auditor-level privileges
A company already uses HPE Aruba Networking ClearPass Policy Manager (CPPM) as the RADIUS server to authenticate wireless clients with 802.1X. You are now configuring 802.1X on AOS-CX switches to authenticate many of the same clients over wired connections. You choose to copy CPPM’s wireless 802.1X service and edit it with a new name and enforcement policy.
What else must be changed for authentication to function correctly?
ARole mapping policy
BAuthentication methods
CAuthentication source
DService rules
You need to create a rule in an HPE Aruba Networking ClearPass Manager (CPPM) role-mapping policy that refers to a ClearPass Device Insight Tag.
Which Type (namespace) should you specify for the rule?
AEndpoint
BTips
CDevice
DApplication
An administrator has configured an AOS-CX switch with the following settings:
port-access role employees
vlan access name employees
The switch is also configured to use CPPM as its RADIUS server.
Which CPPM enforcement profile should be configured to work with this setup?
ARADIUS Enforcement type with Aruba-User-Role VSA set to "employees"
BHPE Aruba Networking Downloadable Role Enforcement type with role name set to "employees"
CHPE Aruba Networking Downloadable Role Enforcement type with gateway role name set to "employees"
DRADIUS Enforcement type with HPE-User-Role VSA set to "employees"
What is one use case for periodically running subnet scans on devices from HPE Aruba Networking ClearPass Policy Manager (CPPM)?
ADetecting devices that fail to comply with rules defined in CPPM posture policies.
BIdentifying issues with authenticating and authorizing clients
CUsing WMI to collect additional information about Windows domain clients
DUsing DHCP fingerprints to determine a client’s device category and OS
A company is deploying HPE Aruba Networking Wireless IDS/IPS (WIDS/WIPS) on AOS-10 APs managed through HPE Aruba Networking Central.
What is one requirement to enable rogue-AP detection?
AA Foundation with Security license for each of the APs
BA manual radio profile that enables non-regulatory channels
CEach VLAN in the network assigned on at least one AP's or AM's port
DOne AM deployed for every one AP deployed
You are proposing HPE Aruba Networking ZTNA to an organization that currently uses a third-party, IPsec-based client-to-site VPN. What is one advantage of ZTNA that should be emphasized?
AZTNA improves security for SaaS applications, which now makes up the majority of remote user traffic.
BZTNA shrinks the attack surface, eliminating publicly exposed ports and reducing the extent of the private network exposed to remote users.
CZTNA is specifically designed to enhance security for Internet of Things (IoT) devices, which are proliferating rapidly and which traditional client-to-site VPNs cannot address.
DZTNA offers no greater security than the current solution, but it makes it much easier for admins to create and maintain consistent policies.
A company plans to use the HPE Aruba Networking ClearPass OnGuard agent to assign posture to clients.
How are the conditions defined under which a client is assigned a specific posture?
ACreate rules directly in a service’s Posture tab.
BCreate rules within a WebAuth enforcement policy.
CCreate the rules directly in a service’s Enforcement tab.
DCreate rules within a posture policy.
You are configuring HPE Aruba Networking SSE. Which use case requires applying a non-default identity in a rule?
Achecking whether a client complies with various security measures as a condition for receiving access to certain websites
Bgranting access to certain applications only to users with certificates signed by a particular CA
Cproviding users management access to HPE Aruba Networking SSE based on the users’ group
Drestricting access to a private web application based on the user's membership in a group
HPE Aruba Networking ClearPass Policy Manager (CPPM) uses a service to authenticate clients. You now want to add rules to the service’s role-mapping policy to assign CPPM roles according to device category. You also need to create a rule that applies the profiling-cppm role to clients that require profiling.
Which condition does HPE Aruba Networking recommend for this rule?
You have created a web-based Health Check Service that references a posture policy. You want the service to initiate a RADIUS change of authorization (CoA) when a client receives either a Healthy or Quarantine posture.
Where do you configure these rules?
AIn a RADIUS enforcement policy
BIn the Agents and Software Updates > OnGuard Settings
CIn the posture policy
DIn a WEBAUTH enforcement policy
A company has HPE Aruba Networking APs running AOS-10 that connect to AOS-CX switches. The APs will:
Authenticate as 802.1X supplicants to HPE Aruba Networking ClearPass Policy Manager (CPPM)
Be assigned the “APs” role on the switches
Have their traffic forwarded locally
What information is required to determine the VLAN settings for the “APs” role?
AWhether the switches are using local user-roles (LURs) or downloadable user-roles (DURs)
BWhether the APs bridge or tunnel traffic on their SSIDs
CWhether the switches have established tunnels with an HPE Aruba Networking gateway
DWhether the APs have static or DHCP-assigned IP addresses
HPE Aruba Networking Central shows a Gateway Threat Count alert in the alert list. How can you obtain more information about what triggered the alert?
AUse HPE Aruba Networking Central tools to run a Network Check on the gateway with which the alert is associated.
BUse Live Monitoring on the gateway to download a packet capture of recent traffic flowing through the gateway.
CCheck the threat list for the gateway associated with the alert. Access threat details and download packet info.
DCheck the gateway’s Audit Trail in HPE Aruba Networking Central for more details about the threats that triggered the alert.
A company uses HPE Aruba Networking Central-managed APs. The APs enforce 802.1X authentication for clients connecting to the MyCompany SSID. Some clients are assigned the contractors role. A firewall rule for the contractors role has been created with this extended action: denylist (or blacklist in older software versions).
Which additional step is required to ensure the action is applied?
AEnable denylisting (blacklisting) in the MyCompany SSID settings.
BEnable denylisting (blacklisting) in contractor role settings.
CEnable Client IPS at the "medium" level in the security settings.
DEnable Client IDS at the "medium" level in the security settings.
The security team asks you to present information about MAC spoofing attempts detected by HPE Aruba Networking ClearPass Policy Manager (CPPM).
What should you do?
AUse ClearPass Insight to run an Active Endpoint Security report.
BShow the security team the CPPM Endpoint Profiler dashboard.
CIntegrate CPPM with ClearPass Device Insight (CPDI) and run a security report on CPDI.
DExport the Access Tracker records on CPPM as an XML file.
A company intends to implement Virtual Network Based Tunneling (VNBT) for a specific user group and place those users on an overlay network with VNI 3000.
Assume an AOS-CX switch is already configured to:
Implement 802.1X with HPE Aruba Networking ClearPass Policy Manager (CPPM)
Participate in an EVPN VXLAN solution that includes VNI 3000
Which setting must be configured in the users’ AOS-CX role to apply VNBT when they connect?
AGateway zone set to "3000" with no gateway role set
BGateway zone set to "vni-3000" with no gateway role set
CAccess VLAN set to the VLAN mapped to VNI 3000
DAccess VLAN ID set to "3000"
You need to examine the applications a device is using and identify changes in application usage across several time ranges.
In which HPE Aruba Networking solution can this information be viewed in an easy-to-read format?
AHPE Aruba Networking ClearPass OnGuard agent installed on the device
BHPE Aruba Networking Central within a device’s Live Monitoring page
CHPE Aruba Networking ClearPass Insight using an Active Endpoint Security report
DHPE Aruba Networking ClearPass Device Insight (CPDI) in the device’s network activity
You are configuring HPE Aruba Networking SSE to identify threats while remote users browse the internet. What is included in the process?
Aintegrating HPE Aruba Networking SSE with a supported third-party antivirus provider
Bdeploying a connector that can reach the remote users
Ccreating a non-default file security profile
Dcreating an external web profile that enables SSL inspection
Community Discussion