HPE Campus Access Mobility Expert (HPE7-A07) HP Practice Exam
QuestionQ1
Connectivity
Save question
You are deploying a new AOS-10 mobility gateway cluster. Because of customer requirements, the gateways must use static IP addresses and may communicate on port 443 only with URLs matching *.central.arubanetworks.com.
How can these gateways be successfully onboarded into HPE Aruba Networking Central?
AChoose Static Activate and Configure:• system name• switch role• ACP FQDN address• uplink port information• IP address and default gateway• DNS IP address• controller country code• timezone and clock• admin password
BChoose Full Setup and Configure:• system name• switch role• ACP FODN address• uplink port information• IP address and default gateway• DNS IP address• controller country code• timezone and clock• admin password
CChoose Static Activate and Configure-• controller VLAN• uplink port information• IP address• default gateway• DNS IP address
DChoose Full Setup and Configure:• controller VLAN• uplink port information• IP address and default gateway• DNS IP address
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ2
Troubleshooting
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ3
Routing
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ4
WLAN
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ5
Routing
0
Community Discussion
No comments yet. Be the first to start the discussion!
That's the end of the preview
It's free
100% of the questions are free for all users. No strings attached.
You configured a tunneled SSID with a captive portal and an HPE Aruba Networking ClearPass Guest Self Registration workflow. During testing, after you launch the self-registration workflow and registration succeeds, the login action displays the following error:
What is the best solution for resolving this error?
AYou need to be connected to the guest SSID while testing.
BYou need to include the root and intermediate certificates in the captive portal certificate for your access points.
CYou need to change the Login Address in ClearPass to securelogin.arubanetworks com.
DYou need to include the root and intermediate certificates in the captive portal certificate for your gateway.
A BGP routing table has several routes to the same destination prefix.
With reference to the table below, which route would be indicated by a > symbol?
AA
BB
CC
DD
EE
A university operates a campus with several buildings divided into east and west wings that are L3-separated. The east wing has 1600 APs, while the west wing has 1200 APs. Each wing has one gateway cluster managed by HPE Aruba Networking Central, and each cluster contains a single 7210 mobility gateway. The gateways use DHCP relay and route every client VLAN.
A new business-critical, real-time faculty application requires users to roam within their wings, but not between wings, with no disconnections or added delay.
Which changes must the network administrator make to meet this requirement successfully, without performance degradation and in accordance with best practices?
Choose two
ARemove the DHCP relay from the gateways and enable the DHCP server instead
BReplace the 7210 mobility gateway in the east wing with a pair of 9012 mobility gateways.
CRun L2 for all SSIDs and permit the users’ VLANs in the gateway's uplinks.
DAdd a single 7210 mobility gateway to each cluster.
EReplace the 7210 mobility gateway in the west wing with a pair of 7030 mobility gateways.
Refer to the exhibits.
An engineer applied the displayed configuration to R1 and R2. However, the routers’ OSPF adjacency never advances beyond the EXSTART/DR state, as shown below.
Which configuration action on either router will enable R1 and R2 to advance past the EXSTART/DR state?
ARemove the layer 3 MTU configuration.
BEnsure the OSPF process is not configured with passive-interface default
CChange the IP address and mask applied to interface 1/1/1
DChange R1 and R2 to a network type of point-to-point.
QuestionQ6
WLAN
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ7
Network Resiliency and virtualization
QuestionQ9
Network Resiliency and virtualization
QuestionQ10
Routing
QuestionQ11
WLAN
QuestionQ12
WLAN
QuestionQ13
Switching
QuestionQ14
Authentication/Authorization
QuestionQ15
Switching
QuestionQ16
Performance Optimization
QuestionQ17
Authentication/Authorization
QuestionQ19
WLAN
QuestionQ20
Troubleshooting
QuestionQ21
WLAN
QuestionQ22
Troubleshooting
QuestionQ23
WLAN
QuestionQ24
Troubleshooting
QuestionQ25
Routing
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Refer to the exhibit.
Which wireless connection phase has just finished?
AL3 authentication and encryption
BMAC Authentication and 4-way handshake
C802.11 enhanced open association
DL2 authentication and encryption
A customer's infrastructure is configured, following best practices, to use both primary and secondary gateway clusters in the SSID profile. What is a valid reason that AP connections are evenly divided between the primary and secondary gateway clusters?
AThe primary gateway cluster is up. but some APs are unable to reach the primary gateway cluster. These APs would connect to the secondary gateway cluster.
BThe primary gateway cluster is up. but some APs cannot reach the secondary gateway cluster These APs would connect to the secondary gateway cluster.
CThe secondary gateway cluster is heterogeneous.
DThe secondary gateway cluster is homogeneous.
A customer's infrastructure follows best practices by using both primary and secondary gateway clusters in the SSID profile. Why are its 144 APs split equally between the primary gateway cluster and the secondary gateway cluster?
AThe primary and secondary gateway clusters are up. but the cluster preemption is not enabled.
BThe primary and secondary gateway clusters are up. and the cluster preemption is enabled.
CThe secondary gateway cluster is a homogeneous cluster with six nodes.
DThe secondary gateway cluster is a heterogeneous cluster with four nodes.
An OSPF router learns a route to an external network through both an E1 and an E2 advertisement. Both routes have identical path costs. Which route will the router prefer?
AThe router will prefer the E1 path.
BThe router will prefer the E2 path.
CThe router will use both paths equally utilizing ECMP.
DBoth routes will be suppressed until the path conflict has been resolved.
Refer to the exhibit.
Which statement is correct?
AThe SSID supports implicit beamforming.
BThe SSID supports sending neighbor reports.
CThe SSID supports RC4 encryption.
DThe SSID supports 802.11ac clients.
A customer wants to let its IT Helpdesk configure IoT devices to connect to one SSID with a unique PSK that cannot be used by other devices. Which solution would you recommend?
AMPSK Local
BMPSK AES with HPE Aruba Networking ClearPass
CMPSK AES with HPE Aruba Networking Central Cloud Authentication
DMPSK AES with MAC Auth
A customer is evaluating device profiles on a CX 6300 switch. The test device has these attributes:
MAC address = 81:cd:93:13:ab:31
LLDP sys-desc = iotcontroller
The test device is assigned the iot-dev role. However, the customer requires the iot-prod role to be applied.
Given the configuration, what causes the iot-dev role to be applied to the device?
AAn external RADIUS server is unreachable.
BThe device-profile precedence order is not configured.
CThe LLDP system description matches the lldp-group configuration.
DThe test device does not support CDP
You configured WPA3-SAE with the following MAC Authentication Role Mapping in HPE Aruba Networking Central Cloud Authentication and Policy:
Assuming all other settings remain at their defaults, a new Android phone connects to the network. Which role is assigned to the client on its first connection?
Aiot-local
Bclient will be rejected network access
Cbyod
Dunmatched-device
A client connected to a tunneled open network is receiving an incorrect VLAN. Your customer has a gateway and provided a packet capture from a switch-port mirror on the upstream switch, along with packet captures from the IPsec tunnel and the GRE tunnel, to help identify the VLAN sent from the controller to the AP.
Where can the VLAN assignment be seen?
AThe GRE tunnel will include the VLAN tag assignment.
BVLAN tag assignment will not be captured in any of the packet captures.
CVLAN tag assignment will be included in the port mirror.
DIPsec tunnel will include the VLAN tag assignment.
ACME has an AOS-CX 6200 VSF switch stack with an uplink oversubscription ratio of 9.6:1. Its low-priority TCP traffic is marked with a yellow DSCP color.
Refer to the exhibit.
The company is considering adding two more nodes to the stack without adding uplinks because of existing wiring constraints. An architect has proposed this configuration:
What is the impact of applying the acmethreshold profile as shown?
Choose two
AAll upper-layer protocol traffic egressing LAG1 will be subject to drop probability
BAll TCP traffic egressing LAG1 will be subject to drop probability
CVoIP packets egressing any queue on LAG1 will more likely be protected from uplink over-utilization
DYellow-flagged TCP traffic egressing LAG1 will be subject to drop probability
EOnly VoIP packets egressing queue 5 on LAG1 will likely be protected from uplink over-utilization
Refer to the exhibit.
Which user role is assigned when a voice client attempts to connect for the first time while the RADIUS server is unavailable?
ACRITICAL_VOICE
BCRITICAL_AUTH
CPRE_AUTH
DDEFAULT_AUTH
A new SSID was created with the security settings shown.
Some, but not every, user reports that their client device cannot connect to this SSID. What is the reason?
AWPA3 Enterprise is not backward compatible with WPA2 Enterprise.
BThe WPA3 Enterprise GCM-256 mode does not support transition mode
CThe primary server's shared key differs from the shared key configured for this server on HPE Aruba Networking Central.
DMAC authentication after a failed 802.1X authentication is not possible as the option "MAC Authentication Fail-Through" is disabled
An AOS-10 multi-site deployment includes sites with AP-only bridged SSIDs and other sites with APs and gateways running tunneled SSIDs. Client session-state synchronization errors occur between secure lab environments and public-facing areas at several sites.
What is causing these issues?
AThe sites with issues are the overlay AP with gateway sites because the connection to HPE Aruba Networking Central is interrupted.
BThe sites with issues are the AP-only deployments because the connection to HPE Aruba Networking Central is interrupted.
CThe DTLS connections are down between APs in the lab and APs in public areas.
DThe affected clients are associated with an SSID with 11r and 11k disabled.
A customer recently deployed a wireless system using AP-535s to provide connectivity for employees responsible for uploading large video files for review. The customer wants to use features that deliver throughput gains for large data uploads.
Which feature can be enabled to satisfy the requirement while also allowing spatially separated clients to access the channel?
AUL MU-MIMO
BDL MU-MIMO
CUL-TXBF
DOFDMA
A customer has a gateway connected to a device on gigabitethernet 0/0/3 and configures an Asset ID TLV on the device for inventory management.
See the exhibit.
The customer reports that the Asset ID is not displayed. What is causing this issue?
ALLDP TX is not enabled
BLLPD-MED needs to be enabled
CMTU size is too small.
DUnknown TLVs cannot be displayed
A network administrator needs to configure an 802.1 X supplicant for a wireless network that includes:
AES encryption
EAP-MSCHAPv2-based user and machine authentication
Server-certificate validation in Microsoft Windows 10
The network administrator creates a WLAN profile and selects the change connection settings option. The administrator then changes the security type to Microsoft: Protected EAP (PEAP) and enables user and machine authentication under Additional Settings.
What must the network administrator do next to complete the task?
AChange default RC4 encryption for AES.
BEnable server certificate validation
CChange the security type to Microsoft: Smart Card or other certificate.
DEnable user authentication.
A customer added third-party USB dongles to the USB ports on their AOS-10 access points. The customer uses AP-615 and AP-635 access points. Each AP connects by a Cat 6A cable to a CX 6300F Class 4 PoE switch. All APs are in the same group in HPE Aruba Networking Central and use the same configuration. However, many dongles do not power up.
Which option will resolve this issue?
AMove the AP-635 access points to a different group in HPE Aruba Networking Central to configure the dongles separately from the AP-615.
BReplace the Class 4 PoE switches with Class 6 PoE switches.
CCreate two separate service profiles in the IoT tab of the HPE Aruba Networking Central configuration settings.
DPerform a "poe disable" followed by a "poe enable" for the switch ports which connect to the APs so that the APs reboot.
Refer to the exhibits.
Which statement is true based on the following CLI output from a CX 6300?
AThere are no active fabric clients on the CX switch with RD 172.16.10.1.
BA wired client with IP address 10.203.1.100 has a host route that is not being properly advertised.
CThe overlay loopback addresses are advertised in the fabric with 24-bit subnet masks.
DA wired client with IP address 10.203.1.100 is on a remote CX 6300 in the fabric with loopback IP address 172.21.11.2.
Community Discussion