Exam Details

  • Exam Code
    :ACMP_6.4
  • Exam Name
    :Aruba Certified Mobility Professional 6.4
  • Certification
    :Aruba Certifications
  • Vendor
    :Aruba
  • Total Questions
    :173 Q&As
  • Last Updated
    :Jun 24, 2025

Aruba Aruba Certifications ACMP_6.4 Questions & Answers

  • Question 141:

    ipaccess-listsession anewone user network 10.1.1.0 255.255.255.0 any permit user any any permit host 10.1.1.1 host 10.2.2.2 any deny A user sends a frame with the following attributes: Source IP: 10.1.1.1 Destination IP: 10.2.2.2 Destination Port: 25 Based on the above Mobility Controller configuration file segment, what will this policy do with the user frame?

    A. The frame is discarded because of the implicit deny all at the end of the policy.

    B. The frame is discarded because of the statement:user host 10.1.1.1 host 10.2.2.2 deny.

    C. The frame is accepted because of the statement:user any any permit.

    D. The frame is accepted because of the statement:user network 10.1.1.0 255.255.255.0 any permit.

    E. This is not a valid policy.

  • Question 142:

    Refer to the following configuration segment for this item.

    netdestination "internal"

    no invert

    network 172.16.43.0 255.255.255.0 position 1

    range 172.16.11.0 172.16.11.16 position 2

    ipaccess-listsession"My-Policy"

    alias "user" alias "internal" service any permit queue low

    A user frame is evaluated against this firewall policy with the following attributes:

    Source IP: 172.17.49.3 Destination IP: 10.100.86.37 Destination Port: 80 Referring to the above file

    segment, how will the frame be handled by this firewall policy?

    A. The frame will be dropped because of the implicit deny all at the end of the netdestination definition.

    B. The frame will be dropped because of the implicit deny all at the end of the firewall policy.

    C. The frame will be forwarded because of the implicit permit all at the end of the firewall policy.

    D. The frame will be passed because there is no service specified in the firewall policy.

    E. The frame will be dropped because there is no service specified in the firewall policy.

  • Question 143:

    Refer to the following configuration segment for this item. ipaccess-listsession anewone user network 172.16.1.0 255.255.255.0 any permit user host 172.16.1.1 any deny user any any permit

    An administrator wants users to have access to all destinations except 172.16.1.1. Based on the above Aruba Mobility Controller configuration segment, which statements best describe this policy? (Choose two)

    A. The rule user host 172.16.1.1 any deny is redundant because of the implicit deny all at the end.

    B. The rule user network 172.16.1.0 255.255.255.0 any permit is redundant.

    C. The two rules user network 172.16.1.0 255.255.255.0 any permit and user host 172.16.1.1 any deny need to be re- sequenced.

    D. The last statement user any any permit is not required

    E. The last statement should be any any any deny

  • Question 144:

    Review the following truncated output from an Aruba controller for this item. (example) #show rights logon access-list List

    Position Name Location

    1 logon-control 2 captiveportal logon-control

    Priority Source Destination Service Action

    1 user any udp 68 deny 2 any any svc-icmp permit 3anyanysvc-dnspermit 4 any any svc-dhcp permit 5 any any svc-natl permit captiveportal

    Priority Source Destination Service Action

    1 user controller svc-htlps dst-nat 8081 2 user any svc-htlp dst-nat 8080 3 user any svc-htlps dst-nat 8081 4 user any svc-htlp-proxy1 dst-nat 8088 5 user any svc-htlp-proxy2 dst-nat 8088 6 user any svc-htlp-proxy3 dst-nat 8088 Based on the above output from an Aruba controller, an unauthenticated user assigned to the logon role attempts to startanhtlp session toIP address 172.16.43.170.

    What will happen?

    A. the user's traffic will be passed to the IP address because of the policy statement:user any svc-htlp dstnat 8080

    B. the user's traffic will be passed to the IP address because of the policy statement:user any svc-htlps dst-nat 8081

    C. the user's traffic will be passed to the IP address because of the policy statement:user any svc-htlpproxy1 dst-nat

    D. the user will not reach the IP address because of the policy statement:user any svc-htlp dst-nat 8080

    E. the user will not reach the IP address because of the implicit deny any any at the end of the policy.

  • Question 145:

    The Aruba Policy Enforcement Firewall (PEF) module supports source network address translation (srcnat).

    Which is a use of this statement in an Aruba configuration?

    A. provide a single source IP address for users in a role

    B. redirect Captive Portal HTTP sessions

    C. redirect Access Points to another Aruba controller

    D. provide IP addresses to clients

    E. redirects clients to Aruba Firewall

  • Question 146:

    When creating a firewall rule what are valid choices for the ServicejApplication field? (Choose three)

    A. Applications

    B. Applications Category

    C. Internet Protocol

    D. Internet Category

    E. Protocol

  • Question 147:

    The Aruba Policy Enforcement Firewall (PEF-NG) module supports destination network address translation (dst-nat). Which is the default use of this statement in an Aruba controller configuration?

    A. source the IP addresses of users to specific IP address

    B. redirectHTTPsessionstoCaptivePortal

    C. redirect Access Points to another Aruba controller

    D. provide a telnet connection to the controller

    E. redirect a SSH session to terminate on the controller

  • Question 148:

    What is true about Global Session ACL? (Choose two)

    A. Any rules will apply to all users in the AP-group

    B. Any rules will apply to all users in the Network

    C. Any rules will apply to all users in the controller

    D. Is in the first position in all roles

    E. When added it is in the first position in selected Role

  • Question 149:

    What are aliases used for?

    A. improve controller performance

    B. simplify the configuration process

    C. tie IP addresses to ports

    D. assign rules to policies

    E. assign policies to roles

  • Question 150:

    Which of the following firewall rules allows a user to initiate an ICMP session to other devices?(Choose two)

    A. localip any svc-icmp permit

    B. user any svc-icmp permit

    C. user user svc-icmp permit

    D. any any svc-icmp permit

    E. mswitch any svc-icmp permit

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Aruba exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your ACMP_6.4 exam preparations and Aruba certification application, do not hesitate to visit our Vcedump.com to find your solutions here.