Pass the HP ACNSP HPE7-A02 Questions and answers with CertsForce

Viewing page 3 out of 4 pages
Viewing questions 21-30 out of questions
Questions # 21:

A company has AOS-CX switches. The company wants to make it simpler and faster for admins to detect denial of service (DoS) attacks, such as ping or ARP floods, launched against the switches.

What can you do to support this use case?

Options:

A.

Deploy an NAE agent on the switches to monitor control plane policing (CoPP).


B.

Configure the switches to implement RADIUS accounting to HPE Aruba Networking ClearPass and enable HPE Aruba Networking ClearPass Insight.


C.

Implement ARP inspection on all VLANs that support end-user devices.


D.

Enabling debugging of security functions on the switches.


Expert Solution
Questions # 22:

A company wants to apply a standard configuration to all AOS-CX switch ports and have the ports dynamically adjust their configuration based on the identity of

the user or device that connects. They want to centralize configuration of the identity-based settings as much as possible.

What should you recommend?

Options:

A.

Having HPE Aruba Networking ClearPass Policy Manager (CPPM) send standard RADIUS AVPs to customize port settings


B.

Having switches pull port configurations dynamically from HPE Aruba Networking Activate


C.

Having switches download user-roles from HPE Aruba Networking gateways


D.

Having switches download user-roles from HPE Aruba Networking ClearPass Policy Manager (CPPM)


Expert Solution
Questions # 23:

A company uses HPE Aruba Networking ClearPass Policy Manager (CPPM) and HPE Aruba Networking ClearPass Device Insight (CPDI) and has integrated the

two. CPDI admins have created a tag. CPPM admins have created rules that use that tag in the wired 802.1X and wireless 802.1X services' enforcement policies.

The company requires CPPM to apply the tag-based rules to a client directly after it learns that the client has that tag.

What is one of the settings that you should verify on CPPM?

Options:

A.

The "Device Sync" setting is set to 1 in the ClearPass Device Insight Integration settings.


B.

Both 802.1X services have the "Profile Endpoints" option enabled and an appropriate CoA profile selected in the Profiler tab.


C.

Both 802.1X services have the "Use cached Role and Posture attributes from the previous sessions" setting.


D.

The "Polling Interval" is set to 1 in the ClearPass Device Insight Integration settings.


Expert Solution
Questions # 24:

A company has HPE Aruba Networking APs running AOS-10 that connect to AOS-CX switches. The APs will:

    Authenticate as 802.1X supplicants to HPE Aruba Networking ClearPass Policy Manager (CPPM)

    Be assigned to the "APs" role on the switches

    Have their traffic forwarded locally

What information do you need to help you determine the VLAN settings for the "APs" role?

Options:

A.

Whether the switches are using local user-roles (LURs) or downloadable user-roles (DURs).


B.

Whether the APs bridge or tunnel traffic on their SSIDs.


C.

Whether the switches have established tunnels with an HPE Aruba Networking gateway.


D.

Whether the APs have static or DHCP-assigned IP addresses.


Expert Solution
Questions # 25:

A ClearPass Policy Manager (CPPM) service includes these settings:

    Role Mapping Policy:

      Evaluate: Select first

      Rule 1 conditions:

        Authorization:AD:Groups EQUALS Managers

        Authentication:TEAP-Method-1-Status EQUALS Success

        Rule 1 role: manager

Rule 2 conditions:

    Authentication:TEAP-Method-1-Status EQUALS Success

    Rule 2 role: domain-comp

Default role: [Other]

Enforcement Policy:

    Evaluate: Select first

    Rule 1 conditions:

      Tips Role EQUALS manager AND Tips Role EQUALS domain-comp

      Rule 1 profile list: domain-manager

Rule 2 conditions:

    Tips Role EQUALS manager

    Rule 2 profile list: manager-only

Rule 3 conditions:

    Tips Role EQUALS domain-comp

    Rule 3 profile list: domain-only

Default profile: [Deny access]

A client is authenticated by the service. CPPM collects attributes indicating that the user is in the Contractors group, and the client passed both TEAP methods.

Which enforcement policy will be applied?

Options:

A.

[Deny Access Profile]


B.

manager-only


C.

domain-manager


D.

domain-only


Expert Solution
Questions # 26:

A company is using HPE Aruba Networking Central SD-WAN Orchestrator to establish a hub-spoke VPN between branch gateways (BGWs) at 1164 site and VPNCs at multiple data centers. What is part of the configuration that admins need to complete?

Options:

A.

In VPNCs’ groups, establish VPN pools to control which branches connect to which VPNCs.


B.

In BGWs’ and VPNCs’ groups, create default IKE policies for the SD-WAN Orchestrator to use.


C.

In BGWs’ groups, select the VPNCs to which to connect in a DC preference list.


D.

At the global level, create default IPsec policies for the SD-WAN Orchestrator to use.


Expert Solution
Questions # 27:

What is a use case for the HPE Aruba Networking ClearPass OnGuard dissolvable agent?

Options:

A.

Continuously monitoring Windows domain clients for compliance


B.

Implementing a one-time compliance scan


C.

Auto-remediating posture issues on clients


D.

Periodically scanning Linux clients for security issues


Expert Solution
Questions # 28:

Question # 28

All of the switches in the exhibit are AOS-CX switches.

What is the preferred configuration on Switch-2 for preventing rogue OSPF routers in this network?

Options:

A.

Disable OSPF entirely on VLANs 10-19.


B.

Configure OSPF authentication on VLANs 10-19 in password mode.


C.

Configure OSPF authentication on Lag 1 in MD5 mode.


D.

Configure passive-interface as the OSPF default and disable OSPF passive on Lag 1.


Expert Solution
Questions # 29:

A company has HPE Aruba Networking APs, which authenticate users to HPE Aruba Networking ClearPass Policy Manager (CPPM).

What does HPE Aruba Networking recommend as the preferred method for assigning clients to a role on the AOS firewall?

Options:

A.

Configure CPPM to assign the role using a RADIUS enforcement profile with a RADIUS:IETF Username attribute.


B.

Configure CPPM to assign the role using a RADIUS enforcement profile with an Aruba-User-Role VSA.


C.

OCreate server rules on the APs to assign clients to roles based on RADIUS IETF attributes returned by CPPM.


D.

Create user rules on the APs to assign clients to roles based on a variety of criteria.


Expert Solution
Questions # 30:

What role can Internet Key Exchange (IKE)/IKEv2 play in an HPE Aruba Networking client-to-site VPN?

Options:

A.

It provides an alternative to IPsec that is suitable for legacy clients.


B.

It provides a more modern and secure alternative to IPsec.


C.

It helps to negotiate the IPsec SA automatically and securely.


D.

It helps remote clients download IPsec profiles for later use.


Expert Solution
Viewing page 3 out of 4 pages
Viewing questions 21-30 out of questions