Pass the HP Aruba-ACNSA HPE6-A78 Questions and answers with CertsForce

Viewing page 2 out of 5 pages
Viewing questions 11-20 out of questions
Questions # 11:

What is a benefit of deploying Aruba ClearPass Device insight?

Options:

A.

Highly accurate endpoint classification for environments with many devices types, including Internet of Things (loT)


B.

visibility into devices' 802.1X supplicant settings and automated certificate deployment


C.

Agent-based analysts of devices' security settings and health status, with the ability to implement quarantining


D.

Simpler troubleshooting of ClearPass solutions across an environment with multiple ClearPass Policy Managers


Expert Solution
Questions # 12:

An MC has a WLAN that enforces WPA3-Enterprise with authentication to HPE Aruba Networking ClearPass Policy Manager (CPPM). The WLAN's default role is set to guest. A Mobility Controller (MC) has these roles configured on it:

    authenticated

    denyall

    guest

    general-access

    guest-logon

    logon

    stateful-dot1x

    switch-logon

    voiceA client authenticates. CPPM returns an Access-Accept with an Aruba-User-Role VSA set to general_access. What role does the client receive?

Options:

A.

guest


B.

logon


C.

general-access


D.

authenticated


Expert Solution
Questions # 13:

You are deploying a new wireless solution with an HPE Aruba Networking Mobility Master (MM), Mobility Controllers (MCs), and campus APs (CAPs). The solution will include a WLAN that uses Tunnel for the forwarding mode and WPA3-Enterprise for the security option.

You have decided to assign the WLAN to VLAN 301, a new VLAN. A pair of core routing switches will act as the default router for wireless user traffic.

Which links need to carry VLAN 301?

Options:

A.

Only links on the path between APs and the core routing switches


B.

Only links on the path between APs and the MC


C.

All links in the campus LAN to ensure seamless roaming


D.

Only links between MC ports and the core routing switches


Expert Solution
Questions # 14:

You have an AOS-8 architecture, consisting of a Mobility Conductor (MC) and Mobility Controllers (MCs). You want to monitor wireless clients’ application usage in the Traffic Analysis dashboard. What is a requirement?

Options:

A.

Configuring packet capturing on the MCs’ data plane


B.

Enabling logging on the users category on the MCs


C.

Discovering the mobility devices in HPE Aruba Networking Central


D.

Enabling firewall visibility and deep packet inspection (DPI) on the MCs


Expert Solution
Questions # 15:

A company with 439 employees wants to deploy an open WLAN for guests. The company wants the experience to be as follows:

*Guests select the WLAN and connect without having to enter a password.

*Guests are redirected to a welcome web page and log in.

The company also wants to provide encryption for the network for devices that are capable. Which security options should you implement for the WLAN?

Options:

A.

Opportunistic Wireless Encryption (OWE) and WPA3-Personal


B.

WPA3-Personal and MAC-Auth


C.

Captive portal and Opportunistic Wireless Encryption (OWE) in transition mode


D.

Captive portal and WPA3-Personal


Expert Solution
Questions # 16:

How does the AOS firewall determine which rules to apply to a specific client's traffic?

Options:

A.

The firewall applies the rules in policies associated with the client's user role.


B.

The firewall applies every rule that includes the client's IP address as the source.


C.

The firewall applies the rules in policies associated with the client's WLAN.


D.

The firewall applies every rule that includes the client's IP address as the source or destination.


Expert Solution
Questions # 17:

Refer to the exhibit, which shows the settings on the company’s MCs.

— Mobility Controller

Dashboard General Admin AirWave CPSec Certificates

Configuration

WLANsv Control Plane Security

Roles & PoliciesEnable CP Sec

Access PointsEnable auto cert provisioning:

You have deployed about 100 new Aruba 335-APs. What is required for the APs to become managed?

Options:

A.

installing CA-signed certificates on the APs


B.

installing self-signed certificates on the APs


C.

approving the APs as authorized APs on the AP whitelist


D.

configuring a PAPI key that matches on the APs and MCs


Expert Solution
Questions # 18:

What is one method for HPE Aruba Networking ClearPass Policy Manager (CPPM) to use DHCP to classify an endpoint?

Options:

A.

It can determine information such as the endpoint OS from the order of options listed in Option 55 of a DHCP Discover packet.


B.

It can respond to a client’s DHCP Discover with different DHCP Offers and then analyze the responses to identify the client OS.


C.

It can snoop DHCP traffic to register the clients’ IP addresses. It then knows where to direct its HTTP requests to actively probe for information about the client.


D.

It can alter the DHCP Offer to insert itself as a proxy gateway. It will then be inline in the traffic flow and can apply traffic analytics to classify clients.


Expert Solution
Questions # 19:

A company with 465 employees wants to deploy an open WLAN for guests. The company wants the experience to be as follows:

    Guests select the WLAN and connect without having to enter a password.

    Guests are redirected to a welcome web page and log in.The company also wants to provide encryption for the network for devices that are capable. Which security options should you implement for the WLAN?

Options:

A.

Opportunistic Wireless Encryption (OWE) and WPA3-Personal


B.

Captive portal and WPA3-Personal


C.

WPA3-Personal and MAC-Auth


D.

Captive portal and Opportunistic Wireless Encryption (OWE) in transition mode


Expert Solution
Questions # 20:

You have deployed a new HPE Aruba Networking Mobility Controller (MC) and campus APs (CAPs). One of the WLANs enforces 802.1X authentication to HPE Aruba Networking ClearPass Policy Manager (CPPM). When you test connecting the client to the WLAN, the test fails. You check ClearPass Access Tracker and cannot find a record of the authentication attempt. You ping from the MC to CPPM, and the ping is successful.

What is a good next step for troubleshooting?

Options:

A.

Renew CPPM's RADIUS/EAP certificate.


B.

Check connectivity between CPPM and a backend directory server.


C.

Check CPPM Event Viewer.


D.

Reset the user credentials.


Expert Solution
Viewing page 2 out of 5 pages
Viewing questions 11-20 out of questions