Pass the HP ACNSP HPE7-A02 Questions and answers with CertsForce

Viewing page 1 out of 4 pages
Viewing questions 1-10 out of questions
Questions # 1:

Refer to the exhibit.

Question # 1

You have verified that AOS-CX Switch-1 has constructed an IP-to-MAC binding table in VLANs 10-19. Now you need to enable ARP inspection for the endpoint connected to Switch-1. What must you do first to prevent traffic disruption?

Options:

A.

Configure ARP inspection on VLANs 10-19 on Switch-2.


B.

Configure DHCP snooping on VLANs 10-19 on Switch-2.


C.

Configure Switch-1 uplinks as trusted ARP inspection ports.


D.

Create a static IP-to-MAC binding on Switch-1 for the DHCP server.


Questions # 2:

A company has a third-party security appliance deployed in its data center. The company wants to pass all traffic for certain clients through that device before forwarding that traffic toward its ultimate destination.

Which AOS-CX switch technology fulfills this use case?

Options:

A.

Virtual Network Based Tunneling (VNBT)


B.

MC-LAG


C.

Network Analytics Engine (NAE)


D.

Device profiles


Questions # 3:

A company wants you to integrate HPE Aruba Networking ClearPass Policy Manager (CPPM) with HPE Aruba Networking ClearPass Device Insight (CPDI).

What is one aspect of the integration that you should explain?

Options:

A.

CPPM no longer supports any Device Profiler features and relies on CPDI for this profile information.


B.

CPDI must be configured as an audit server on CPPM for the integration to be successful.


C.

CPDI must have security analysis disabled on it for the integration to be successful.


D.

CPPM can submit profile information to CPDI, but if CPDI derives a different classification, CPDI takes precedence.


Questions # 4:

A company has HPE Aruba Networking APs running AOS-10 and managed by HPE Aruba Networking Central. The company also has AOS-CX switches. The

security team wants you to capture traffic from a particular wireless client. You should capture this client's traffic over a 15 minute time period and then send the

traffic to them in a PCAP file.

What should you do?

Options:

A.

Go to the client's AP in HPE Aruba Networking Central. Use the "Security" page to run a packet capture.


B.

Access the CLI for the client's AP. Set up a mirroring session between its radio and a management station running Wireshark.


C.

Access the CLI for the client's AP's switch. Set up a mirroring session between the AP's port and a management station running Wireshark.


D.

Go to that client in HPE Aruba Networking Central. Use the "Live Events" page to run a packet capture.


Questions # 5:

A company uses HPE Aruba Networking ClearPass Device Insight (CPDI) (the standalone application option). In the details for a generic device cluster, you see a

recommendation for "Windows 8/10" with 70% accuracy.

What does this mean?

Options:

A.

CPDI has detected that these devices match about 70% of the system rule for defining "Windows 8/10" devices.


B.

CPDI has matched these devices against several, conflicting system rules. 70% of those rules are for "Windows 8/10" devices.


C.

CPDI has grouped this cluster with similar classified devices. 70% of those classified devices are "Windows 8/10."


D.

CPDI has used MAC OUI to group these devices together. The average device's MAC address matches 70% of the "Windows 8/10" OUI.


Questions # 6:

You are establishing a cluster of HPE Aruba Networking ClearPass servers. (Assume that they are running version 6.9.).

For which type of certificate it is recommended to install a CA-signed certificate on the Subscriber before it joins the cluster?

Options:

A.

Database


B.

HTTPS


C.

RADIUS/EAP


D.

RadSec


Questions # 7:

A company has been running Gateway IDS/IPS on its gateways in IDS mode for several weeks. The company wants to transition to IPS mode.

What is one step you should recommend?

Options:

A.

Disable traffic inspection and reboot before re-enabling traffic inspection with the new mode.


B.

Change the mode on one gateway at a time to establish a smoother transition period.


C.

Consider applying a stricter IPS policy to minimize issues during the transition period.


D.

Check for legitimate traffic that has been flagged as a threat and allow list the associated rules.


Questions # 8:

An AOS-CX switch has this admin user account configured on it:

netadmin in the operators group.

You have configured these commands on an AOS-CX switch:

tacacs-server host cp.example.com key plaintext &12xl,powmay7855

aaa authentication login ssh group tacacs local

aaa authentication allow-fail-through

A user accesses the switch with SSH and logs in as netadmin with the correct password. When the switch sends a TACACS+ request to the ClearPass server at cp.example.com, the server does not send a response. Authentication times out.

What happens?

Options:

A.

The user is logged in and granted operator access.


B.

The user is logged in and allowed to enter auditor commands only.


C.

The user is logged in and granted administrators access.


D.

The user is not allowed to log in.


Questions # 9:

A company wants HPE Aruba Networking ClearPass Policy Manager (CPPM) to respond to Syslog messages from its Check Point firewall. You have added the

firewall as an event source and set up an event service. However, test Syslog messages are not triggering the expected actions.

What is one CPPM setting that you should check?

Options:

A.

ClearPass Device Insight integration is disabled.


B.

The Check Point Extension is installed through ClearPass Guest.


C.

The CoA delay value is set to 0 on the server.


D.

Ingress Event Dictionaries for Check Point messages are enabled.


Questions # 10:

A company wants to use HPE Aruba Networking ClearPass Policy Manager (CPPM) to profile Linux devices. You have decided to schedule a subnet scan of the devices' subnets. Which additional step should you complete before scheduling the scan?

Options:

A.

Set up SSH accounts on CPPM and map them to the Linux devices' subnets.


B.

Enable WMI probing in the cluster-wide parameters.


C.

Enable the Data Port in the ClearPass server settings and connect that port to the network.


D.

Configure SNMP in the network device settings for the switches that support the Linux devices.


Viewing page 1 out of 4 pages
Viewing questions 1-10 out of questions