Month End Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the HP ACNSP HPE7-A02 Questions and answers with CertsForce

Viewing page 4 out of 4 pages
Viewing questions 31-40 out of questions
Questions # 31:

You have configured an AOS-CX switch to implement 802.1X on edge ports. Assume ports operate in the default auth-mode. VolP phones are assigned to the

"voice" role and need to send traffic that is tagged for VLAN 12.

Where should you configure VLAN 12?

Options:

A.

As the trunk native VLAN on edge ports and the trunk native VLAN on the "voice" role


B.

As a trunk allowed VLAN on edge ports and the trunk native VLAN in the "voice" role


C.

As the trunk native VLAN in the "voice" role (and not in the edge port settings)


D.

As the allowed trunk VLAN in the "voice" role (and not in the edge port settings)


Expert Solution
Questions # 32:

An admin has configured an AOS-CX switch with these settings:

port-access role employees

vlan access name employees

This switch is also configured with CPPM as its RADIUS server.

Which enforcement profile should you configure on CPPM to work with this configuration?

Options:

A.

RADIUS Enforcement type with HPE-User-Role VSA set to "employees"


B.

HPE Aruba Networking Downloadable Role Enforcement type with role name set to "employees"


C.

HPE Aruba Networking Downloadable Role Enforcement type with gateway role name set to "employees"


D.

RADIUS Enforcement type with Aruba-User-Role VSA set to "employees"


Expert Solution
Questions # 33:

A company has HPE Aruba Networking Central-managed APs. The company wants to block all clients connected through the APs from using YouTube.

Which steps should you take?

Options:

A.

Deploy gateways and have the APs tunnel traffic to the gateways. Then, enable the gateway IDS/IPS engine.


B.

Enable Client IPS at the "custom" level, and then specify the check for YouTube.


C.

Enable WebCC on all client firewall roles. Then, create WebCC category rules that deny suspicious URLs.


D.

Enable DPI. Then, create application rules to deny YouTube on the firewall roles.


Expert Solution
Questions # 34:

A company is implementing a client-to-site VPN based on tunnel-mode IPsec.

Which devices are responsible for the IPsec encapsulation?

Options:

A.

Gateways at the remote clients' locations and devices accessed by the clients at the main site


B.

The remote clients and devices accessed by the clients at the main site


C.

The remote clients and a gateway at the main site


D.

Gateways at the remote clients' locations and a gateway at the main site


Expert Solution
Questions # 35:

A company has HPE Aruba Networking APs and AOS-CX switches, as well as HPE Aruba Networking ClearPass. The company wants CPPM to have HTTP User-

Agent strings to use in profiling devices.

What can you do to support these requirements?

Options:

A.

Add the CPPM server's IP address to the IP helper list in all client VLANs on routing switches.


B.

Schedule periodic subnet scans of all client subnets on CPPM.


C.

Configure mirror sessions on the APs and switches to copy client HTTP traffic to CPPM.


D.

On the APs and switches, configure a redirect to ClearPass Guest in the role for devices being profiled.


Expert Solution
Questions # 36:

A company is using HPE Aruba Networking Central SD-WAN Orchestrator to establish a hub-spoke VPN between branch gateways (BGWs) at 1444 site and

VPNCs at multiple data centers.

What is part of the configuration that admins need to complete?

Options:

A.

At the global level, create default IPsec policies for the SD-WAN Orchestrator to use.


B.

In BGWs' groups, select the VPNCs to which to connect in a DC preference list.


C.

In VPNCs' groups, establish VPN pools to control which branches connect to which VPNCs.


D.

In BGWs' and VPNCs' groups, create default IKE policies for the SD-WAN Orchestrator to use.


Expert Solution
Questions # 37:

A company has a variety of HPE Aruba Networking solutions, including an HPE Aruba Networking infrastructure and HPE Aruba Networking ClearPass Policy Manager (CPPM). The company passes traffic from the corporate LAN destined to the data center through a third-party SRX firewall. The company would like to further protect itself from internal threats. What is one solution that you can recommend?

Options:

A.

Have the third-party firewall send Syslogs to CPPM, which can work with network devices to lock internal attackers out of the network.


B.

Add ClearPass Device Insight (CPDI) to the solution, integrate it with the third-party firewall to develop more complete device profiles.


C.

Configure CPPM to poll the third-party firewall for a broad array of information about internal clients, such as profile and posture.


D.

Use tunnel mode SSIDs and user-based tunneling (UBT) on AOS-CX switches to pass all internal traffic directly through the third-party firewall.


Expert Solution
Questions # 38:

An AOS-CX switch has this admin user account configured on it:

netadmin in the operators group.

You have configured these commands on an AOS-CX switch:

tacacs-server host cp.example.com key plaintext &12xl,powmay7855

aaa authentication login ssh group tacacs local

aaa authentication allow-fail-through

A user accesses the switch with SSH and logs in as netadmin with the correct password. When the switch sends a TACACS+ request to the ClearPass server at cp.example.com, the server does not send a response. Authentication times out.

What happens?

Options:

A.

The user is logged in and granted operator access.


B.

The user is logged in and allowed to enter auditor commands only.


C.

The user is logged in and granted administrators access.


D.

The user is not allowed to log in.


Expert Solution
Questions # 39:

A company has HPE Aruba Networking APs running AOS-10 that connect to AOS-CX switches. The APs will:

. Authenticate as 802.1X supplicants to HPE Aruba Networking ClearPass Policy Manager (CPPM)

. Be assigned to the "APs" role on the switches

. Have their traffic forwarded locally

What information do you need to help you determine the VLAN settings for the "APs" role?

Options:

A.

Whether the APs have static or DHCP-assigned IP addresses


B.

Whether the switches are using local user-roles (LURs) or downloadable user-roles (DURs)


C.

Whether the switches have established tunnels with an HPE Aruba Networking gateway


D.

Whether the APs bridge or tunnel traffic on their SSIDs


Expert Solution
Questions # 40:

A company wants you to integrate HPE Aruba Networking ClearPass Policy Manager (CPPM) with HPE Aruba Networking ClearPass Device Insight (CPDI).

What is one aspect of the integration that you should explain?

Options:

A.

CPPM no longer supports any Device Profiler features and relies on CPDI for this profile information.


B.

CPDI must be configured as an audit server on CPPM for the integration to be successful.


C.

CPDI must have security analysis disabled on it for the integration to be successful.


D.

CPPM can submit profile information to CPDI, but if CPDI derives a different classification, CPDI takes precedence.


Expert Solution
Viewing page 4 out of 4 pages
Viewing questions 31-40 out of questions