Pass the HP ACNSP HPE7-A02 Questions and answers with CertsForce

Viewing page 2 out of 4 pages
Viewing questions 11-20 out of questions
Questions # 11:

Assume that an AOS-CX switch is already implementing DHCP snooping and ARP inspection successfully on several VLANs.

What should you do to help minimize disruption time if the switch reboots?

Options:

A.

Configure the switch to act as an ARP proxy.


B.

Create static IP-to-MAC bindings for the DHCP and DNS servers.


C.

Save the IP-to-MAC bindings to external storage.


D.

Configure the IP helper address on this switch, rather than a core routing switch.


Questions # 12:

You have installed an HPE Aruba Networking Network Analytic Engine (NAE) script on an AOS-CX switch to monitor a particular function.

Which additional step must you complete to start the monitoring?

Options:

A.

Reboot the switch.


B.

Enable NAE, which is disabled by default.


C.

Edit the script to define monitor parameters.


D.

Create an agent from the script.


Questions # 13:

A company has HPE Aruba Networking infrastructure devices. The devices authenticate clients to HPE Aruba Networking ClearPass Policy Manager (CPPM). You want CPPM to track information about clients, such as their IP addresses and their network bandwidth utilization. What should you set up on the network infrastructure devices to help that happen?

Options:

A.

Logging with CPPM configured as a Syslog server.


B.

Dynamic authorization enabled in the RADIUS settings for CPPM.


C.

RADIUS accounting to CPPM, including interim updates.


D.

An IF-MAP interface with CPPM as the destination.


Questions # 14:

A company has HPE Aruba Networking APs running AOS-10 and managed by HPE Aruba Networking Central. The company also has AOS-CX switches. The security team wants you to capture traffic from a particular wireless client. You should capture this client’s traffic over a 15-minute time period and then send the traffic to them in a PCAP file. What should you do?

Options:

A.

Access the CLI for the client’s AP. Set up a mirroring session between its radio and a management station running Wireshark.


B.

Go to the client’s AP in HPE Aruba Networking Central. Use the "Security" page to run a packet capture.


C.

Go to that client in HPE Aruba Networking Central. Use the "Live Events" page to run a packet capture.


D.

Access the CLI for the client’s AP's switch. Set up a mirroring session between the AP’s port and a management station running Wireshark.


Questions # 15:

A company uses HPE Aruba Networking ClearPass Policy Manager (CPPM) as a TACACS+ server to authenticate managers on its AOS-CX switches. You want

to assign managers to groups on the AOS-CX switch by name.

How do you configure this setting in a CPPM TACACS+ enforcement profile?

Options:

A.

Add the Shell service and set autocmd to the group name.


B.

Add the Shell service and set priv-Ivl to the group name.


C.

Add the Aruba:Common service and set Aruba-Admin-Role to the group name.


D.

Add the Aruba:Common service and set Aruba-Priv-Admin-User to the group name.


Questions # 16:

An AOS-CX switch has been configured to implement UBT to two HPE Aruba Networking gateways that implement VRRP on the users' VLAN. What correctly describes how the switch tunnels UBT users' traffic to those gateways?

Options:

A.

The switch always sends the users' traffic to the VRRP master.


B.

The switch always sends all users' traffic to the primary gateway configured in the UBT zone.


C.

The switch always load shares the users' traffic across both gateways.


D.

The switch always sends all users' traffic to the gateway assigned as the active device designed gateway.


Questions # 17:

Question # 17

You have downloaded a packet capture that you generated on HPE Aruba Networking Central. When you open the capture in Wireshark, you see the output shown in the

exhibit.

What should you do in Wireshark so that you can better interpret the packets?

Options:

A.

Choose to decode UDP port 5555 packets as ARUBA_ERM and set the Aruba ERM Type to 0.


B.

Edit preferences for IEEE 802.11 and chose to ignore the Protection bit with IV.


C.

Apply the following display filter: wlan.fc.type == 1.


D.

Edit the Enabled Protocols and make sure that 802.11, GRE, and Aruba_ERM are enabled.


Questions # 18:

A company has AOS-CX switches and HPE Aruba Networking APs, which run AOS-10 and bridge their SSIDs. Company security policies require 802.1X on all edge ports, some of which connect to APs. How should you configure the auth-mode on AOS-CX switches?

Options:

A.

Leave all edge ports in client auth-mode and configure device auth-mode in the AP role.


B.

Configure all edge ports in client auth-mode.


C.

Configure all edge ports in device auth-mode.


D.

Leave all edge ports in device auth-mode and configure client auth-mode in the AP role.


Questions # 19:

You are setting up an HPE Aruba Networking VIA solution for a company. You have already created a VPN pool with IP addresses for the remote clients. During

tests, however, the clients do not receive IP addresses from that pool.

What is one setting to check?

Options:

A.

That the pool uses valid, public IP addresses that are assigned to the company


B.

That the pool is associated with the role to which the VIA clients are being assigned


C.

That the pool uses an IP subnet that is different from any subnet configured on the VPNC


D.

That the pool is referenced in the clients' VIA Connection Profile


Questions # 20:

HPE Aruba Networking Central displays an alert about an Infrastructure Attack that was detected. You go to the Security > RAPIDS events and see that the attack was "Detect adhoc using Valid SSID." What is one possible next step?

Options:

A.

Make sure that you have tuned the threshold for that check as false positives are common for it.


B.

Make sure that clients have updated drivers, as faulty drivers are a common explanation for this attack type.


C.

Use HPE Aruba Networking Central floorplans or the detecting AP identities to locate the general area for the threat.


D.

Look for the IP address associated with the offender and then check for that IP address among HPE Aruba Networking Central clients.


Viewing page 2 out of 4 pages
Viewing questions 11-20 out of questions