You recently configured a switch for 802.1X authentication using HPE Aruba Networking ClearPass. A security administrator observes events in ClearPass Event Viewer with this description:
RADIUS authentication attempt from unknown NAD (10.10.1.10:1812)
Which command should be used to identify the configuration issue?
Ashow ip source-interface radius
Bshow aaa authentication-server radius
Cshow radius-server shared-secret
Dshow radius-server detail
A client wants to use the HPE Aruba Networking Switch MultiEdit Software function in HPE Aruba Networking Central.
Which option is available?
AUse CLI scripts and apply them to selected switches.
BRun the same NAE scripts for selected switches.
CUse templates and apply them to selected switches.
DApply a configuration to an interface range for selected switches.
Based on the configuration shown below, identify the proper event sequence for wired DHCP profiling of IoT devices using HPE Aruba Networking ClearPass.
Drag & Drop
ClearPass processes the MAC authentication and sends RADIUS Accept with Aruba-User-Role=PROFILING VSA.
ClearPass sends a Change of Authorization to the switch.
MAC address is learned on the port and MAC auth is triggered.
The client device is connected to the switch and the port is now up.
The client device sends DHCP DISCOVER which is relayed to ClearPass and used to update the endpoint database.
The device has network access on the IOT VLAN.
The device is re-authenticated and the final role is assigned using the Aruba-User-Role=IOT VSA.
The switch assigns a role with the PROFILING VLAN to the client device.
Refer to the exhibit.
Acme Corp has VM workloads running downstream from ToR-1 and has observed performance degradation. They suspect that the ToR-1 uplinks are periodically overutilized. A partner has recommended migrating the legacy 1U Core-1 and Core-2 switches to the CX 6400 series.
Which aspects of this platform would address the customer’s problem while following HPE Aruba Networking best practices?
Choose two
AMC-LAG permits Core-1 and Core-2 to present the edge 802.3ad device as a common “system ID”.
BThe CX 6400 series supports multiple active forwarding pathways from ToR-1 based on multi-region design.
CThe proposed solutions backplane stacking permits the directly connected ESXI hosts to load balance using active LACP.
DThe port density of the CX 6400 series chassis permits the direct connection of the VM hypervisors to the core.
EThe proposed new core’s VSF capability allows multiple active forwarding pathways from ToR-1 based while eliminating the need for STP.
QuestionQ6
Network Stack
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ8
Connectivity
QuestionQ9
Connectivity
QuestionQ10
Connectivity
QuestionQ11
Security
QuestionQ13
Troubleshooting
QuestionQ14
Network Resiliency and virtualization
QuestionQ16
Authentication/Authorization
QuestionQ17
Switching
QuestionQ18
Security
QuestionQ19
Network Resiliency and virtualization
QuestionQ20
Connectivity
QuestionQ22
Authentication/Authorization
QuestionQ23
Switching
QuestionQ24
Routing
QuestionQ25
Security
QuestionQ26
Security
QuestionQ27
Switching
QuestionQ29
Troubleshooting
QuestionQ30
Network Resiliency and virtualization
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Refer to the exhibit.
IGMPv3 is enabled on both VSX switches. Which switch becomes the IGMP querier for clients connected to the Acc-1 switch?
AAgg-2
Bboth Agg-1 and Agg-2
CAgg-1
DActive gateway IP will be used as IGMP querier.
You are deploying gateways with Zero-Touch Provisioning (ZTP) for a network. Which two requirements apply to the switchport connection?
Choose two
AYou must use port GE 0/0/1 on the gateway
BThe switchport needs to be untagged with Internet access
CThe switchport needs to be configured with IP address 172.16.0.254
DJumbo frames must be enabled
EThe gateway needs to be provided an IP address through DHCP
A client deployed 655 APs in a project to upgrade the network at a large public venue. The customer reports problems integrating the new Bluetooth sensor system that will help the facilities team monitor when the venue is in use.
What could be causing the issue?
AAP-655 does not have Bluetooth radio
Bthroughput
CPoE
DBluetooth needs an advanced AP license.
Match each network technology with the customer requirement.
Drag & Drop
ECMP
EVPN
VNI
VXLAN
Establish redundant links between the aggregation and core layers.
Extend layer 2 across multiple sites.
Identify individual layer 2 segments in an overlay.
Minimize configuration steps to establish tunnels between sites.
The customer needs ARP inspection configured for VLAN 6 on port 1/1/2, but not on port 1/1/1. Which commands establish this configuration?
R1 has not learned OSPF routes from a directly connected neighboring router. Based on the exhibit’s show command output, which statement identifies a misconfiguration that would cause the router’s neighbor state to remain stuck at 2-WAY/DROther?
AThe other router’s directly connected interface is not attached to the default VRF.
BThere is a hello timer mismatch.
CBoth router’s OSPF priority are set to 0.
DThere is an L2 interface MTU mismatch.
You need to describe VSX to a colleague. Select the three items considered best practices for implementing VSX on AOS-CX.
Choose three
AAllow VLAN 1 on all trunks in order to facilitate ZTP for downstream devices.
BSet a VSX system-mac manually to simplify switch replacement of the primary if required.
CAdjust MTU on the ISL link to permit transport of jumbo frames if endpoints require it.
DConfigure all VLANs manually on both the primary and secondary nodes before enabling vsx-sync.
EAdjust the default keepalive timers to match or exceed the ISL hold interval.
FUse a direct L3 circuit for the keepalive connection between both nodes.
You are configuring an HPE Aruba Networking Gateway Cluster using AOS-10. Which statements are true about 802.1X functionality when used with gateways?
Choose two
AUsers on L3-connected gateways need to perform a full authentication after re-associated on the AP.
BThe UDG remains fixed on L2-connected gateways but not on L3-connected gateways.
CRegardless of using gateways, the CoA message is always sent to the APs.
DThe gateways are used as a RADIUS proxy, while the AP is the authenticator.
EThe gateways act as RADIUS Proxy only in Tunneled and Bridged Mode.
An IT administrator uses AOS-CX switches to send TCP port 22 traffic from the switch port to a remote server for analysis. The administrator now wants to store it locally so it can be downloaded and used later if they change their mind about the approach to take.
When enabling DHCPv4 snooping on an AOS-CX access switch, what change must be made so that clients can obtain an IP address from the DHCP servers?
A
B
Cdhcpv4-snooping trust interface 1/1/51-1/1/52
D
An AOS-10 gateway cluster is managed by HPE Aruba Networking Central. During a failover, what behavior is expected for client traffic?
AClient traffic is disrupted during the AP bootstrap.
BClient state synchronization is supported on each failover.
CClient IPv4 multicast session failover is not supported.
DClient state synchronization is supported on the first failover.
Match each network technology to the customer requirement.
Drag & Drop
EVPN
VNI
VSX
VXLAN
Aggregate links across multiple switches.
Extend layer 2 across multiple sites.
Identify individual layer 2 segments in an overlay.
Minimize configuration steps to establish tunnels between sites.
You have a functioning MAC-authentication solution for IoT devices using HPE Aruba Networking ClearPass, and you want to dynamically alter a device role according to DHCP fingerprints.
Your security team updated the applicable ClearPass configuration so it returns the IoT Aruba-User-Role VSA when devices meet the relevant profiling rules. The ClearPass appliance is behind a firewall.
You deployed the configuration shown below.
Which actions are required for the solution to function?
Choose two
AEnable TLS for the RADIUS server
BEnable Dynamic Authorization in the global context
CConfigure the firewall UDP port 3799 from all switches to ClearPass
DConfigure the firewall to allow UDP port 3799 from ClearPass to all switches
EConfigure an IP helper address with the ClearPass IP address on the IoT VLAN SVI
A network administrator is deploying a new VoIP solution. They need the AOS-CX switches to advertise the proper DSCP priority to the physical IP phones.
Which switch features are required to implement this solution?
Choose two
ALLDP med network-policy
BVoice VLAN
CLLDP med DSCP
DLLDP dot3 mfs
EPriority-Flow Control (PFC)
Refer to the exhibit.
The customer has VSX clusters at two locations, interconnected over an MC-LAG interface. You need an SVI to provide a seamless experience for clients connected to the Edge-1 and Edge-2 switches to reach the default route when resources are moved between the switches.
What must be done according to HPE Aruba Networking best practices?
AConfigure the active gateway and use the same virtual IP and vMAC.
BConfigure active forwarding and use the same virtual IP and a different vMAC.
CConfigure the VXLAN interface and bind required SVIs as VNIs.
DConfigure VRRP and load balance traffic using member properties.
Refer to the exhibit.
A conference venue must secure independent network users from one another on its network.
What can be done to stop clients from communicating with each other through the customer’s equipment?
AWith Edge-1 and Edge-2 connected clients, a community VLAN can be used.
BWith Edge-2 connected clients, an isolated VLAN can be used.
CWith Edge-1 connected clients, an isolated VLAN can be used.
DWith Edge-1 and Edge-2 connected clients, an isolated VLAN can be used.
Refer to the four numbered steps in the exhibit.
Which action occurs first when applying the role-to-role ACL to traffic from mobile device M1 to role H2?
AThe edge switch acts as the intermediate node and transfers the Group Policy ID over static VXLAN to dynamic VXLAN tunnel and forwards the packet to switch A1.
BThe AP forwards the packet from M1 to gateway 1.
CSwitch A1 determines the destination role based on destination MAC or destination IP and enforces role-to-role ACLs.
DGateway 1 forwards the traffic over the static VXLAN tunnel to the edge switch; this packet carries the Group Policy ID corresponding to the role of M1.
A customer asked you to create a new IDF design for a large office building. A junior staff member compiled the technical requirements and produced a design to satisfy them. You have been asked to review the following portion of that design:
CUSTOMER REQUIREMENTS:
preference for stackable switches
Each closet must contain a single virtual switch.
dual 10Gbps fiber uplinks from each closet
capacity for 500 edge ports in each closet; no additional capacity is required
lowest-cost AOS-CX switch that satisfies all requirements
PROPOSED DESIGN:
nine (9) AOS-CX 6200M (R8Q69A: Class4 PoE 4SFP+ switch (R8Q68A) HPE Aruba Networking 6200M 46G 4SFP+ switch) in each closet
switches configured in a VSF (Virtual Switching Framework) stack, with auto-stacking enabled
uplinks configured on the first and last stack members
Does the proposed solution satisfy the technical requirements?
ANo. The proposed design does not meet the capacity requirements.
BYes. The proposed design meets the customer’s requirements.
CNo. The proposed design does not meet the requirements for uplink connectivity.
DNo. The proposed design is not the lowest-cost AOS-CX switch for this project.
An IT administrator is setting up an HPE Aruba Networking User Experience Insight (UXI) sensor. During the initiation process, the administrator observes that the LED is orange.
What does an orange LED indicate?
AThe sensor needs multi-rate port but this port is only standard 1G port
BThe sensor is still booting
CThe sensor cannot connect to the UXI cloud
DThis is a G6E UXI sensor and does not have enough PoE power
Refer to the exhibit.
A VSX cluster has already been configured. You must validate the correct configuration for the Edge-1 switch, which connects to a CCTV provider that will install its switching infrastructure. The CCTV switches do not support STP.
What must be configured on the Edge-1 switch ports connected to CCTV-SW1 and CCTV-SW2 to prevent loop issues in the existing setup while providing automatic recovery?
Aconfigure lag with lacp fallback for CCTV switch ports
Bconfigure spanning-tree and TN-guard timeout for CCTV switch ports
Cconfigure spanning-tree with bpdu-guard timeout values for CCTV switch ports
Dconfigure spanning-tree with udld for CCTV switch ports
Community Discussion