A network administrator accesses HPE Aruba Networking Central and notices that visitors consume too much internet bandwidth, starving employee traffic when accessing an external service. Therefore, the administrator wants to limit wireless bandwidth to 50 Mbps in both directions among all users in the voice role and no more than 10 Mbps in both directions for YouTube traffic. Deep packet inspection, web content classification, and firewall visibility are enabled.
Which configurations are required to accomplish this task? (Choose two.)
A campus topology uses VSX with a collapsed core topology. The customer added redundant SFP+ transceivers and reconfigured their mobility gateways from a single link to an aggregate link. You are asked to verify the CLI output for the link aggregation configuration for one of the mobility gateway cluster members below.
What is a valid configuration?
A
B
C
Refer to the exhibits.
An engineer has applied the above configuration to R1 and R2. However, the router's OSPF adjacency never progresses past the "EXSTART/DR" state as shown below.
Which configuration action on either router will allow R1 and R2 to progress past the "EXSTART/DR" state?
ARemove the layer 3 MTU configuration.
BEnsure the OSPF process is not configured with passive-interface default
CChange the IP address and mask applied to interface 1/1/1
DChange R1 and R2 to a network type of point-to-point.
Refer to the exhibit.
Which statement is true?
AThe SSID supports implicit beamforming.
BThe SSID supports sending neighbor reports.
CThe SSID supports RC4 encryption.
DThe SSID supports 802.11ac clients.
You created a new SSID with the security settings shown in the exhibit.
Some, but not all, users complain that client devices are unable to connect to this SSID. What is the reason for this?
AWPA3 Enterprise is not backward compatible with WPA2 Enterprise.
BThe WPA3 Enterprise GCM-256 mode does not support transition mode
CThe primary server's shared key differs from the shared key configured for this server on HPE Aruba Networking Central.
DMAC authentication after a failed 802.1X authentication is not possible as the option "MAC Authentication Fail-Through" is disabled
Question 6
Authentication/Authorization
0
Question 7
Routing
Question 8
Authentication/Authorization
Question 9
Troubleshooting
Question 10
Routing
Question 11
Network Stack
Question 12
Troubleshooting
Question 13
Security
Question 14
Troubleshooting
Question 15
Connectivity
Question 16
Routing
Question 17
Troubleshooting
Question 18
Routing
Question 19
WLAN
Question 20
WLAN
Question 21
WLAN
Question 22
Authentication/Authorization
Question 23
WLAN
Question 24
Switching
Question 25
WLAN
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ad
Want a break from the ads?
Become a Supporter and enjoy a completely ad-free experience, plus unlock Learn Mode, Exam Mode, AstroTutor AI, and more.
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Refer to the exhibit.
Which user role will be assigned when a voice client tries to connect for the first time, but the RADIUS server is unavailable?
ACRITICAL_VOICE
BCRITICAL_AUTH
CPRE_AUTH
DDEFAULT_AUTH
HOTSPOT -
An administrator is creating a fabric with HPE Aruba Networking Central NetConductor in HPE Aruba Networking Central. Considering an EVPN VXLAN fabric, click on the most appropriate layer to be configured as a Route-Reflector Persona.
A customer is planning to add IoT devices that connect wirelessly to the existing 802.1 X SSID. The customer will use HPE Aruba Networking ClearPass to authenticate the IoT devices by MAC address but other devices will still need to authenticate by only 802.1X.
Refer to the exhibit.
The customer provided the current configuration and reported their non-IoT 802.1X devices are no longer able to connect. Which configuration change can be made to fix the issue?
ARemove mac-authentication from the WLAN configuration.
BModify opmode wpa3-aes-gcm-256 to opmode wpa2-aes.
CAdd l2-auth-failthrough to the WLAN configuration.
DModify max-authentication failures to 0.
A deployment using AP-635s is connected to a stack of CX 6300s as shown.
The output of the show LACP interfaces shows the following:
What is causing this issue?
Ae0 is connected to a smart rate interface, and e1 is connected to a non-smart rate interface.
BThe AP is configured with LACP active.
CSpanning tree and loop protect are enabled on both AP uplink ports.
DEach AP interface is connected to a routed-only interface on different networks.
A BGP routing table contains multiple routes to the same destination prefix.
Referring to the table below, which route would be marked with a ">" symbol?
AA
BB
CC
DD
EE
You want to configure an MTU of 9198 for a routed lag interface on a CX 6300 switch. Which configuration achieves this?
A
B
C
D
A customer with a gateway connected to a device on gigabitethernet 0/0/3 configures an Asset ID TLV on the device for inventory management.
Refer to the exhibit.
The customer mentions the Asset ID is not shown. What is causing the issue?
ALLDP TX is not enabled
BLLPD-MED needs to be enabled
CMTU size is too small.
DUnknown TLVs cannot be displayed
Your customer asked for help to apply an ACL for wireless guest users with the following criteria:
Wi-Fi guests are on VLAN 555 -
allow internet access
only allow access to public DNS servers
deny access to all internal networks except for any DHCP server
These session ACLs are already present in the CLI of the mobility gateway group:
You have access to the CLI. Which user role meets all the criteria?
A
B
C
D
You deployed UBT to securely tunnel traffic from user desktop PCs connected behind VoIP phones. All other non-UBT clients are connected to a different network. After the deployment, users reported interruptions to their phone service.
What is the cause of this issue?
ABroadcast/multicast packets are copied to both the tunnel and locally, causing duplicate packets and network instability
BThe UBT client broadcast/multicast packets returned to the same switch pod and corrupted the phone's MAC table
CThe VoIP multicast group was not created because IGMP snooping is not enabled on the UBT client-assigned VLAN
DThe UBT source interface is not configured correctly on the switch interface to support the PC and VoIP traffic simultaneously
You are deploying a new AOS-10 mobility gateway cluster. Due to customer requirements, the gateways must be configured with static IP addresses and are restricted from communicating using port 443 to any URLs except for *.central.arubanetworks.com.
How would you onboard these gateways successfully into HPE Aruba Networking Central?
AChoose Static Activate and Configure:• system name• switch role• ACP FQDN address• uplink port information• IP address and default gateway• DNS IP address• controller country code• timezone and clock• admin password
BChoose Full Setup and Configure:• system name• switch role• ACP FODN address• uplink port information• IP address and default gateway• DNS IP address• controller country code• timezone and clock• admin password
CChoose Static Activate and Configure-• controller VLAN• uplink port information• IP address• default gateway• DNS IP address
DChoose Full Setup and Configure:• controller VLAN• uplink port information• IP address and default gateway• DNS IP address
Refer to the exhibits.
Which statement is true given the following CLI output from a CX 6300?
AThere are no active fabric clients on the CX switch with RD 172.16.10.1.
BA wired client with IP address 10.203.1.100 has a host route that is not being properly advertised.
CThe overlay loopback addresses are advertised in the fabric with 24-bit subnet masks.
DA wired client with IP address 10.203.1.100 is on a remote CX 6300 in the fabric with loopback IP address 172.21.11.2.
Your customer added third-party USB dongles to the USB ports of their AOS-10 access points. The customer uses AP-615 and AP-635. Each AP is connected with a Cat 6A cable to a CX 6300F Class 4 PoE switch. All APs are in the same group in HPE Aruba Networking Central and share the same configuration. However, many of the dongles do not come up.
Which option will solve this issue?
AMove the AP-635 access points to a different group in HPE Aruba Networking Central to configure the dongles separately from the AP-615.
BReplace the Class 4 PoE switches with Class 6 PoE switches.
CCreate two separate service profiles in the IoT tab of the HPE Aruba Networking Central configuration settings.
DPerform a "poe disable" followed by a "poe enable" for the switch ports which connect to the APs so that the APs reboot.
An OSPF router has learned a path to an external network by both an E1 and an E2 advertisement. Both routes have the same path cost. Which path will the router prefer?
AThe router will prefer the E1 path.
BThe router will prefer the E2 path.
CThe router will use both paths equally utilizing ECMP.
DBoth routes will be suppressed until the path conflict has been resolved.
What directly affects the MCS used by wireless stations? (Choose two.)
Afrequency band
BSNR
Cchannel utilization
Dretry rate
Enumber of connected clients
A customer is deploying a new warehouse with AP-634 APs in the United States with mobile devices that can operate in the 6GHz spectrum. All testing and RF analyses were performed during the POC using AP-635 APs in a different location. During the deployment, they noticed fewer 6GHz channels were broadcasting in the air.
Why would the AP-634 deployment have a lesser amount of broadcasting channels?
AThe AP-634 APs do not have an advanced subscription
BThe AP-634 AP s persona was configured in the HPE Aruba Networking Central group as Standard Power.
CThe AP-635 APs received different allowable 6GHz channels from the AFC service versus the AP-634 APs due to the РОС running in a different location.
DThe AP-634 APs cannot broadcast all 6Ghz channels due to regulatory restrictions.
Which data transmission method provides the most efficient use of airtime for VoIP traffic?
AOFDM
BOFDMA
CTWT
DMU-MIMO
You configured a bridged mode SSID with WPA3-Enterprise and EAP-TLS security. When you connect an Active Directory joined client that has valid client certificates, HPE Aruba Networking ClearPass shows the following error:
What is needed to resolve this issue?
AModify your ACX-AD authentication source to include the UPN in the search.
BRecreate the SSID in tunneled mode.
CEnable authorization in your Authentication Method.
DConfigure ClearPass to trust the client certificate.
Refer to the exhibit.
A university runs its own TV station in the city. The IT department deploys a multimedia server so the TV productions can be sent out to the entire campus over the IP network using multicast-based communications. In order to improve the bandwidth consumption, PIM Sparse Mode and IGMP Snooping features are enabled.
When wireless users join the multicast groups, all users connected to the same WLAN experience poor network performance. However, wired users are not affected in this way. While troubleshooting, the network administrator saves the packet captures shown in the exhibit and concludes that all users, even those not joining the multicast group, receive the same multicast flow at slow speeds.
Which features should the network administrator enable to fix the problem?
ADynamic Multicast Optimization and UCC QoS correction
BUCC QoS correction and Multicast Transmission Optimization
CDynamic Multicast Optimization and Multicast Transmission Optimization
DARP broadcast conversion into unicast and Multicast Transmission Optimization
What is the recommended configuration to ensure link aggregation is consistent in a campus topology using VSX with two aggregation switches and downlinks to access switches?
AKeep the MTU values at the default setting for GRE and VXLAN communications.
BUse the command "vsx-sync mclag-interfaces" under the VSX context.
CUse the command "vsx-sync active-gateways" under the VSX context.
DUse a custom LACP hash algorithm for improved load balancing.
A customer would like to allow their IT Helpdesk to configure IoT devices to connect to a single SSID using a unique PSK that other devices cannot use. Which solution would you recommend?
AMPSK Local
BMPSK AES with HPE Aruba Networking ClearPass
CMPSK AES with HPE Aruba Networking Central Cloud Authentication