Big Halloween Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the HP Aruba Certified Professional - Campus Access HPE7-A01 Questions and answers with CertsForce

Viewing page 2 out of 5 pages
Viewing questions 11-20 out of questions
Questions # 11:

What is one advantage of using OCSP vs CRLs for certificate validation?

Options:

A.

reduces latency between the time a certificate is revoked and validation reflects this status


B.

less complex to implement


C.

higher availability for certificate validation


D.

supports longer certificate validity periods


Expert Solution
Questions # 12:

What is an Aruba-recommended best practice for hardening that only applies to Aruba CX 6300 series switches with dedicated management ports?

Options:

A.

Implement a control plane ACL to limit access to approved IPs and/or subnets


B.

Manually enable Enhanced Security Mode from a console session.


C.

Disable all management services on the default VRF.


D.

Create a dedicated management VRF, and assign the management port to it.


Expert Solution
Questions # 13:

A company with 10,281 employees recently deployed new HPE Aruba Networking Access Points at different branch offices. Wireless 802.IX authentication will be against a RADIUS server in the cloud. The security team is concerned that the traffic between the AP and the RADIUS server will be exposed.

What is the appropriate solution for this scenario?

Options:

A.

Enable IPSec under Data Handling in HPE Aruba Networking Central


B.

Configure RedSec on the AP and the RADIUS server.


C.

Enable EAP-TLS on all wireless devices. Enable EAP-TTLS on all wireless devices.


Expert Solution
Questions # 14:

A new network design is being considered to minimize client latency in a high-density environment. The design needs to do this by eliminating contention overhead by dedicating subcarriers to clients.

Which technology is the best match for this use case?

Options:

A.

OFDMA


B.

MU-MIMO


C.

QWMM


D.

Channel Bonding


Expert Solution
Questions # 15:

The administrator notices that wired guest users that have exceeded their bandwidth limit are not being disconnected Access Tracker in ClearPass indicates a disconnect CoA message is being sent to the AOS-CX switch.

An administrator has performed the following configuration

Question # 15

What is the most likely cause of this issue?

Options:

A.

Change of Authorization has not been globally enabled on the switch


B.

The SSL certificate for CPPM has not been added as a trust point on the switch


C.

There is a mismatch between the RADIUS secret on the switch and CPPM.


D.

There is a time difference between the switch and the ClearPass Policy Manager


Expert Solution
Questions # 16:

A company recently deployed new Aruba Access Points at different branch offices Wireless 802.1X authentication will be against a RADIUS server in the cloud. The security team is concerned that the traffic between the AP and the RADIUS server will be exposed.

What is the appropriate solution for this scenario?

Options:

A.

Enable EAP-TLS on all wireless devices


B.

Configure RadSec on the AP and Aruba Central.


C.

Enable EAP-TTLS on all wireless devices.


D.

Configure RadSec on the AP and the RADIUS server


Expert Solution
Questions # 17:

Which statements regarding Aruba NAE agents are true? (Select two )

Options:

A.

A single NAE script can be used by multiple NAE agents


B.

NAE agents are active at all times


C.

NAE agents will never consume more than 10% of switch processor resources


D.

NAE scripts must be reviewed and signed by Aruba before being used


E.

A single NAE agent can be used by multiple NAE scripts.


Expert Solution
Questions # 18:

Which statement best describes QoS?

Options:

A.

Determining which traffic passes specified quality metrics


B.

Scoring traffic based on the quality of the contents


C.

Identifying specific traffic for special treatment


D.

Identifying the quality of the connection


Expert Solution
Questions # 19:

Two AOS-CX switches are configured with VSX at the the Access-Aggregation layer where servers attach to them An SVI interface is configured for VLAN 10 and serves as the default gateway for VLAN 10. The ISL link between the switches fails, but the keepalive interface functions. Active gateway has been configured on the VSX switches.

Question # 19

What is correct about access from the servers to the Core? (Select two.)

Options:

A.

Server 1 can access the core layer via the keepalrve link


B.

Server 2 can access the core layer via the keepalive link


C.

Server 2 cannot access the core layer.


D.

Server 1 can access the core layer via both uplinks


E.

Server 1 and Server 2 can communicate with each other via the core layer


F.

Server 1 can access the core layer on only one uplink


Expert Solution
Questions # 20:

Your manufacturing client is deploying two hundred wireless IP cameras and fifty headless scanners in their warehouse. These new devices do not support 802.1X authentication.

How can HPE Aruba enhance security for these new IP cameras in this environment?

Options:

A.

Use MPSK Local to automatically provide unique pre-shared Keys for devices.


B.

Aruba ClearPass performs the 802.1X authentication and installs a certificate.


C.

MPSK provides for each device in the WLAN to have its own unique pre-shared Key.


D.

MPSK Local will allow the cameras to share a rey and the scanners to share a different


Expert Solution
Viewing page 2 out of 5 pages
Viewing questions 11-20 out of questions