Exit demo HPE6-A78 Aruba Certified Network Security Associate PDF format · free preview

HP HPE6-A78 - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/hpe6-a78.html

Question 1
Single choice

An MC has a WLAN that enforces WPA3-Enterprise with authentication to HPE Aruba Networking ClearPass Policy Manager (CPPM). The WLAN's default role is set to guest. A Mobility Controller (MC) has these roles configured on it:

authenticated
denyall
guest
general-access
guest-logon
logon
stateful-dot1x
switch-logon
voiceA client authenticates. CPPM returns an Access-Accept with an Aruba-User-Role VSA set to general_access.

What role does the client receive?

A.

guest

B.

logon

C.

general-access

D.

authenticated

Question 2
Single choice

Two wireless clients, client 1 and client 2, are connected to an ArubaOS Mobility Controller. Subnet 10.1.10.10/24 is a network of servers on the other side of the ArubaOS firewall. The exhibit shows all three firewall rules that apply to these clients.

Which traffic is permitted?

A.

an HTTPS request from client 1 to 10.1.10.10 and an HTTPS response from 10.1.10.10 to client 1

B.

an HTTPS request from client 1 to 10.1.10.10 and an HTTPS request from 10.1.10.11 to client 1

C.

an HTTPS request from 10.1.10.10 to client 1 and an HTTPS re-sponse from client 1 to 10.1.10.10

D.

an HTTPS request from client 1 to client 2 and an HTTPS request from client 2 to client

Question 3
Single choice

A company has Aruba Mobility Controllers (MCs), Aruba campus APs, and ArubaOS-CX switches. The company plans to use ClearPass Policy Manager (CPPM) to classify endpoints by type. The company is contemplating the use of ClearPass's TCP fingerprinting capabilities.

What is a consideration for using those capabilities?

A.

ClearPass admins will need to provide the credentials of an API admin account to configure on Aruba devices.

B.

You will need to mirror traffic to one of CPPM's span ports from a device such as a core routing switch.

C.

ArubaOS-CX switches do not offer the support necessary for CPPM to use TCP fingerprinting on wired endpoints.

D.

TCP fingerprinting of wireless endpoints requires a third-party Mobility Device Management (MDM) solution.

Question 4
Single choice

What is an Authorized client as defined by ArubaOS Wireless Intrusion Prevention System (WIP)?

A.

a client that has a certificate issued by a trusted Certification Authority (CA)

B.

a client that is not on the WIP blacklist

C.

a client that has successfully authenticated to an authorized AP and passed encrypted traffic

D.

a client that is on the WIP whitelist.

Question 5
Single choice

You need to set up Aruba network infrastructure devices for management with SNMP. The SNMP server has this SNMPv3 user configured on it: username: airwave auth algorithm: sha auth key: fyluqp18@S!

9a priv algorithm: aes priv key: 761oxaiaoeu19& What correctly describes the setup on the infrastructure device?

A.

You must configure a user with the same name and keys, but can choose algorithms that meet the device's needs.

B.

You must configure the "airwave" server as an authorized user. Then, configure a separate user for this device with its own keys.

C.

You must configure a user with the same name and algorithms, but the keys should be unique to this device.

D.

You must configure a user with exactly the same name, algorithms, and keys.

Question 6
Single choice

A client has accessed an HTTPS server at myhost1.example.com using Chrome. The server sends a certificate that includes these properties:

Subject name: myhost.example.com
SAN: DNS: myhost.example.com; DNS: myhost1.example.com Extended Key Usage (EKU): Server
authentication
Issuer: MyCA_SigningThe server also sends an intermediate CA certificate for MyCA_Signing, which is signed by MyCA.

The client's Trusted CA Certificate list does not include the MyCA or MyCA_Signing certificates.Which factor or factors prevent the client from trusting the certificate?

A.

The client does not have the correct trusted CA certificates.

B.

The certificate lacks a valid SAN.

C.

The certificate lacks the correct EKU.

D.

The certificate lacks a valid SAN, and the client does not have the correct trusted CA certificates.

Question 7
Single choice

A company with 465 employees wants to deploy an open WLAN for guests. The company wants the experience to be as follows:

Guests select the WLAN and connect without having to enter a password. Guests are redirected to a welcome web page and log in.The company also wants to provide encryption for the network for devices that are capable.

Which security options should you implement for the WLAN?

A.

Opportunistic Wireless Encryption (OWE) and WPA3-Personal

B.

Captive portal and WPA3-Personal

C.

WPA3-Personal and MAC-Auth

D.

Captive portal and Opportunistic Wireless Encryption (OWE) in transition mode

Question 8
Single choice

You are checking the Security Dashboard in the Web UI for your AOS solution and see that Wireless Intrusion Prevention (WIP) has discovered a rogue radio operating in ad hoc mode with open security.

What correctly describes a threat that the radio could pose?

A.

It could be attempting to conceal itself from detection by changing its BSSID and SSID frequently.

B.

It could open a backdoor into the corporate LAN for unauthorized users.

C.

It is running in a non-standard 802.11 mode and could effectively jam the wireless signal.

D.

It is flooding the air with many wireless frames in a likely attempt at a DoS attack.

Question 9
Single choice

You are troubleshooting an authentication issue for Aruba switches that enforce 802 IX10 a cluster of Aruba ClearPass Policy Manager (CPPMs) You know that CPPM Is receiving and processing the authentication requests because the Aruba switches are showing Access-Rejects in their statistics.
However, you cannot find the record tor the Access-Rejects in CPPM Access Tracker

What is something you can do to look for the records?

A.

Make sure that CPPM cluster settings are configured to show Access-Rejects

B.

Verify that you are logged in to the CPPM Ul with read-write, not read-only, access

C.

Click Edit in Access viewer and make sure that the correct servers are selected.

D.

Go to the CPPM Event Viewer, because this is where RADIUS Access Rejects are stored.

Question 10
Single choice

A company has HPE Aruba Networking Mobility Controllers (MCs), campus APs, and AOS-CX switches.
The company plans to use HPE Aruba Networking ClearPass Policy Manager (CPPM) to classify endpoints by type. This company is using only CPPM and no other HPE Aruba Networking ClearPass solutions.

The HPE Aruba Networking ClearPass admins tell you that they want to use HTTP User-Agent strings to help profile the endpoints.

What should you do as a part of setting up Mobility Controllers (MCs) to support this requirement?

A.

Create datapath mirrors that use the CPPM's IP address as the destination.

B.

Create an IF-MAP profile, which specifies credentials for an API admin account on CPPM.

C.

Create control path mirrors to mirror HTTP traffic from clients to CPPM.

D.

Create a firewall whitelist rule that permits HTTP and CPPM's IP address.

Showing 10 of 167 questions · Unlock the full set