Pass the HP Aruba Certified ClearPass Expert (ACCX) HPE6-A81 Questions and answers with CertsForce

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

A customer is troubleshooting the OnGuard Client Activity and is looking into the Live Monitoring -> OnGuard Activity section. What is the Status field representing for this client ?

Question # 1

Options:

A.

the Client health status is HEALTHY


B.

the Client has been successfully profiled


C.

the Client is online and sends keep-alive messages


D.

the Client is successful authenticated


Expert Solution
Questions # 2:

Refer to the exhibit.

Question # 2

Question # 2

Question # 2

The users connecting to a wireless SSIO "secure-HS-5007" were being processed by an incorrect 802.1 X service created for VIP access and the user gets deny access. The customer has sent you the screenshot to get your support to resolve the issue What changes will you suggest to fix it?

Options:

A.

To the HS_Building 802.1 X service, add another service rule condition with VIP access Aruba-Essid-Name and leave it in same position


B.

In the HS_Building 802.1X service, remove the service rule condition with Aruba controller location name and leave it in same position


C.

Delete the HSBuilding 802 IX service, odd VIP access Aruba-Essid-Name as fourth condition to WSBuilding Aruba 802 1X service


D.

In the HSBuilding 802. IXservice. change the Authentication method for AMCAuth for VIP access and leave it in same position


Expert Solution
Questions # 3:

Refer to the exhibit.

Question # 3

A customer is trying to configure a TACACS Authentication Service for administrative what could be the reason for the Login Status REJECT?

Options:

A.

The password used by the administrative user is wrong.


B.

The Enforcement profile used is not a TACACS profile.


C.

The Read-only Administrator role does not exist on the Controller.


D.

The Enforcement profile is not designed to be used on Aruba Controller


Expert Solution
Questions # 4:

The customer has a 19.940 loT devices connected to the network and would like to use Allow All Mac Auth to authenticate the users and enforce the action based on the condition defined with the fingerprint details of the device. Which Authorization source would you use to decide the access of the devices?

Options:

A.

Clear Pass Profiler Database


B.

Endpoint Database


C.

Local User Database


D.

Guest Device Database


Expert Solution
Questions # 5:

A customer has a Clear Pass cluster deployment with four servers, two servers at the data center and two servers at a large remote site connected over an SO-WAN solution. The customer would like to implement OnGuard. Guest Self-Registration, and 802.1 X authentication across their entire environment. During testing the customer is complaining that users connecting to an Instant Cluster Employee S5ID at the remote site, with the OnGuard Persistent Agent installed are randomly getting their health check missed.

What could be a possible cause of this behavior?

Options:

A.

The traffic on the TCP port 6658 is congested due to the fact that this port is also used by the IPSec keep-alive packets of the SO-WAN solution.


B.

The OnGuard Clients are automatically mapped to the Policy Manager Zone based on their IP range but an ACL on the switch could be blocking access.


C.

The Aruba-user-role received by the IAP is filtering the TCP port 6658 to the Clear Pass servers and after 10 seconds the SSL fallback gets activated and randomly generates the issue


D.

The ClearPass Policy Manager zones have been defined but the local IP subnets have not but properly mapped to the zones and the OnGuard Agent might connect to any of the servers in the cluster.


Expert Solution
Questions # 6:

Refer to the exhibit.

Question # 6

What enforcement profile will be assigned to a client who has successfully completed the user and machine authentication with UNKNOWN posture token?

Options:

A.

Redirect to Aruba OnBoard Portal


B.

Redirect to Aruba Quarantine Profile


C.

Redirect to Aruba Dissolvable_page Profile


D.

Deny Access Profile


Expert Solution
Questions # 7:

Refer to the exhibit.

Question # 7

Question # 7

The customer configured a guest operator access by creating a custom operator profile and the built-in universal ClearPass profile mapping translation rule. When he tests the setup, he gets authentication failed. Using the streenshots sent by the customer as a reference, what would suggest to the customer to fix the issue?

Options:

A.

To map the operator profile name HS_Receptionist in the translation rule value field


B.

To re-enter the correct username and password for the Active Directory user Mike07.


C.

To correct the case sensitive attribute name in the enforcement profile to admin_privileges


D.

To verify if the username Mike07 has the Active Directory Title attribute set as Reception.


Expert Solution
Questions # 8:

Refer to the exhibit.

Question # 8

You are doing a ClearPass PoC at a customer site with a single Aruba Mobility Controller. The customer asked for a demonstration of a simple Web Login functionality. You used a service template to create the guest services. During testing, the user gets redirected back to the weblogin page with an Authentication failed message The guest configurations on the Aruba Mobility Controller are configured correctly Why would the guest fail to authenticate successfully?

Options:

A.

The authentication source mapped in the service is incorrect It should be mapped as [Guest Device Repository! (Local SQL DB].


B.

The Unique-Device- Count does not allow any Client devices. Update the Enforcement policy condition: Unique-Device-Count.


C.

The username and/or password used for authentication is incorrect Re-enter the correct password on the weblogin page.


D.

The username used for authentication does not exist in the Guest User Database. Create a new user and authenticate again


Expert Solution
Questions # 9:

A customer has acquired another company that has its own Active Directory infrastructure. The 802 1X PEAP authentication works with the customer's original Active Directory servers but the customer would like to authenticate users from the acquired company as well.

What steps are required, in regards to the Authentication Sources, in order to support this request? (Select two.)

Options:

A.

Create a new Authentication Source, type Active Directory.


B.

Create a new Authentication Source, type Generic LDAP.


C.

Add the new AD server(s) as backup into the existing Authentication Source.


D.

There is no need to join ClearPass to the new AD domain.


E.

Join the ClearPass server(s) to the new AD domain.


Expert Solution
Questions # 10:

The customer has configured the guest self-registration with sponsor approval. The guest users that the sponsor email and the other requested details while registering the account but the users were able to complete the authentication and access the internet without the sponsor's approval.

What configuration settings will you check to make this setup work?

Options:

A.

Check if sponsor name field is enabled in the register form page


B.

Check if sponsor email field is enabled in the register form page


C.

Check if authentication option n is enabled in the self-registration page enabled.


D.

Check if sponsor confirmation is enabled in the self-registration page


Expert Solution
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions