Big 11.11 Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

HP Aruba Certified Network Security Expert Written Exam HPE6-A84 Question # 15 Topic 2 Discussion

HP Aruba Certified Network Security Expert Written Exam HPE6-A84 Question # 15 Topic 2 Discussion

HPE6-A84 Exam Topic 2 Question 15 Discussion:
Question #: 15
Topic #: 2

Refer to the scenario.

A customer requires these rights for clients in the “medical-mobile” AOS firewall role on Aruba Mobility Controllers (MCs):

HPE6-A84 Question 15Permitted to receive IP addresses with DHCP

HPE6-A84 Question 15Permitted access to DNS services from 10.8.9.7 and no other server

HPE6-A84 Question 15Permitted access to all subnets in the 10.1.0.0/16 range except denied access to 10.1.12.0/22

HPE6-A84 Question 15Denied access to other 10.0.0.0/8 subnets

HPE6-A84 Question 15Permitted access to the Internet

HPE6-A84 Question 15Denied access to the WLAN for a period of time if they send any SSH traffic

HPE6-A84 Question 15Denied access to the WLAN for a period of time if they send any Telnet traffic

HPE6-A84 Question 15Denied access to all high-risk websites

External devices should not be permitted to initiate sessions with “medical-mobile” clients, only send return traffic.

The exhibits below show the configuration for the role.

HPE6-A84 Question 15

There are multiple issues with this configuration. What is one change you must make to meet the scenario requirements? (In the options, rules in a policy are referenced from top to bottom. For example, “medical-mobile” rule 1 is “ipv4 any any svc-dhcp permit,” and rule 8 is “ipv4 any any any permit”.)


A.

In the “medical-mobile” policy, move rules 2 and 3 between rules 7 and 8.


B.

In the “medical-mobile” policy, change the subnet mask in rule 3 to 255.255.248.0.


C.

Move the rule in the “apprf-medical-mobile-sacl” policy between rules 7 and 8 in the “medical-mobile” policy.


D.

In the “medical-mobile” policy, change the source in rule 8 to “user.”


Get Premium HPE6-A84 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.