HP HPE6-A84 - Questions & Answers
Free preview · every answer includes a full explanation
Product page: https://prepkeys.com/hpe6-a84.html
Refer to the scenario.
A customer is using an AOS 10 architecture with Aruba APs and Aruba gateways (two per site). Admins have implemented auto-site clustering for gateways with the default gateway mode disabled. WLANs use tunneled mode to the gateways.
The WLAN security is WPA3-Enterprise with authentication to an Aruba ClearPass Policy Manager
(CPPM) cluster VIP. RADIUS communications use RADIUS, not RadSec.
For which devices does CPPM require network device entries?
Refer to the scenario.
A customer has asked you to review their AOS-CX switches for potential vulnerabilities. The configuration
for these switches is shown below:



What is one immediate remediation that you should recommend?
You are reviewing an endpoint entry in ClearPass Policy Manager (CPPM) Endpoints Repository.
What is a good sign that someone has been trying to gain unauthorized access to the network?
You want to use Device Insight tags as conditions within CPPM role mapping or enforcement policy rules.
What guidelines should you follow?
Refer to the scenario.
A customer is migrating from on-prem AD to Azure AD as its sole domain solution. The customer also manages both wired and wireless devices with Microsoft Endpoint Manager (Intune).
The customer wants to improve security for the network edge. You are helping the customer design a ClearPass deployment for this purpose. Aruba network devices will authenticate wireless and wired clients to an Aruba ClearPass Policy Manager (CPPM) cluster (which uses version 6.10).
The customer has several requirements for authentication. The clients should only pass EAP-TLS authentication if a query to Azure AD shows that they have accounts in Azure AD. To further refine the clients' privileges, ClearPass also should use information collected by Intune to make access control decisions.
The customer wants you to configure CPPM to collect information from Intune on demand during the authentication process.
What should you tell the Intune admins about the certificates issued to clients?
Refer to the scenario.
A customer has an AOS10 architecture that is managed by Aruba Central. Aruba infrastructure devices authenticate clients to an Aruba ClearPass cluster.
In Aruba Central, you are examining network traffic flows on a wireless IoT device that is categorized as "Raspberry Pi" clients. You see SSH traffic. You then check several more wireless IoT clients and see that they are sending SSH also.
You want an easy way to communicate the information that an IoT client has used SSH to Aruba ClearPass Policy Manager (CPPM).
What step should you take?
Refer to the scenario.
A customer requires these rights for clients in the "medical-mobile" AOS firewall role on Aruba Mobility Controllers (MCs):
1. Permitted to receive IP addresses with DHCP
2. Permitted access to DNS services from 10.8.9.7 and no other server
3. Permitted access to all subnets in the 10.1.0.0/16 range except denied access to 10.1.12.0/22
4. Denied access to other 10.0.0.0/8 subnets
5. Permitted access to the Internet
6. Denied access to the WLAN for a period of time if they send any SSH traffic
7. Denied access to the WLAN for a period of time if they send any Telnet traffic
8. Denied access to all high-risk websites
External devices should not be permitted to initiate sessions with "medical-mobile" clients, only send return traffic.
The exhibits below show the configuration for the role.

There are multiple issues with this configuration. What is one change you must make to meet the scenario requirements? (In the options, rules in a policy are referenced from top to bottom. For example, "medical-mobile" rule 1 is "ipv4 any any svc-dhcp permit," and rule 8 is "ipv4 any any any permit".)
Refer to the scenario.
A customer has an Aruba ClearPass cluster. The customer has AOS-CX switches that implement 802.1X authentication to ClearPass Policy Manager (CPPM).
Switches are using local port-access policies.
The customer wants to start tunneling wired clients that pass user authentication only to an Aruba gateway cluster. The gateway cluster should assign these clients to the "eth-internet" role. The gateway should also handle assigning clients to their VLAN, which is VLAN 20.
The plan for the enforcement policy and profiles is shown below:

The gateway cluster has two gateways with these IP addresses:
Gateway 1
1. VLAN 4085 (system IP) = 10.20.4.21
2. VLAN 20 (users) = 10.20.20.1
3. VLAN 4094 (WAN) = 198.51.100.14
Gateway 2
1. VLAN 4085 (system IP) = 10.20.4.22
2. VLAN 20 (users) = 10.20.20.2
3. VLAN 4094 (WAN) = 198.51.100.12
VRRP on VLAN 20 = 10.20.20.254
The customer requires high availability for the tunnels between the switches and the gateway cluster. If one gateway falls, the other gateway should take over its tunnels. Also, the switch should be able to discover the gateway cluster regardless of whether one of the gateways is in the cluster.
Assume that you are using the "myzone" name for the UBT zone.
Which is a valid minimal configuration for the AOS-CX port-access roles?
What is a common characteristic of a beacon between a compromised device and a command and control server?
Refer to the scenario.
A customer requires these rights for clients in the "medical-mobile" AOS firewall role on Aruba Mobility Controllers (MCs):
1. Permitted to receive IP addresses with DHCP
2. Permitted access to DNS services from 10.8.9.7 and no other server
3. Permitted access to all subnets in the 10.1.0.0/16 range except denied access to 10.1.12.0/22
4. Denied access to other 10.0.0.0/8 subnets
5. Permitted access to the Internet
6. Denied access to the WLAN for a period of time if they send any SSH traffic
7. Denied access to the WLAN for a period of time if they send any Telnet traffic
8. Denied access to all high-risk websites
External devices should not be permitted to initiate sessions with "medical-mobile" clients, only send return traffic.
The exhibits below show the configuration for the role.

What setting not shown in the exhibit must you check to ensure that the requirements of the scenario are met?