Skip to main content

HPE6-A15 Real Exam Questions

Aruba Certified Clearpass Professional 6.5

105 questions available · Page 1 of 11

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

Based on the Policy configuration shown, which VLAN will be assigned when a user with ClearPass role Engineer authenticates to the network successfully using connection protocol WEBAUTH?

  1. A

    Deny Access

  2. B

    Employee VLAN

  3. C

    Internet VLAN

  4. D

    Full Access VLAN

Show answer and explanation

Correct answer: B

Question 2 Multiple choice

What must be configured to enable RADIUS authentication with ClearPass on a network access device (NAD)? (Select two.)

  1. A

    the ClearPass server must have the network device added as a valid NAD

  2. B

    the ClearPass server certificate must be installed on the NAD

  3. C

    a matching shared secret must be configured on both the ClearPass server and NAD

  4. D

    an NTP server needs to be set up on the NAD

  5. E

    a bind username and bind password must be provided

Show answer and explanation

Correct answers: A, C

Question 3 Single choice

Refer to the exhibit.

Based on the configuration of the create_user form shown, which statement accurately describes the status?

  1. A

    The email field will be visible to guest users when they access the web login page.

  2. B

    The visitor_company field will be visible to operators creating the account.

  3. C

    The visitor_company field will be visible to the guest users when they access the web login page.

  4. D

    The visitor_phone field will be visible to the guest users in the web login page.

  5. E

    The visitor_phone field will be visible to operators creating the account.

Show answer and explanation

Correct answer: A

Explanation

References:
https://community.arubanetworks.com/t5/AAA-NAC-Guest-Access-BYOD/expire-timezone-field-is-not-showing-up-on-the-create-user-form/ta-p/250230

Question 4 Multiple choice

Which types of files are stored in the Local Shared Folders database in ClearPass? (Select two.)

  1. A

    Software image

  2. B

    Backup files

  3. C

    Log files

  4. D

    Device fingerprint dictionaries

  5. E

    Posture dictionaries

Show answer and explanation

Correct answers: B, C

Question 5 Single choice

Refer to the exhibit.

Based on the Enforcement Profile configuration shown, which statement accurately describes what is sent?

  1. A

    A limited access VLAN value is sent to the Network Access Device.

  2. B

    An unhealthy role value is sent to the Network Access Device.

  3. C

    A message is sent to the Onguard Agent on the client device.

  4. D

    A RADIUS CoA message is sent to bounce the client.

  5. E

    A RADIUS access-accept message is sent to the Controller

Show answer and explanation

Correct answer: C

Explanation

The OnGuard Agent enforcement policy retrieves the posture token. If the token is HEALTHY it returns a healthy message to the agent and bounces the session. If the token is UNHEALTHY it returns an unhealthy message to the agent and bounces the session.

References:
CLEARPASS ONGUARD CONFIGURATION GUIDE (July 2015), page 27

Question 6 Single choice

Refer to the exhibit.

What can be concluded from the Access Tracker output shown?

  1. A

    The client used incorrect credentials to authenticate to the network.

  2. B

    ClearPass does not have a service enabled for MAC authentication.

  3. C

    The client MAC address is not present in the Endpoints table in the CrearPass database.

  4. D

    The RADIUS client on the Windows server failed to categorize the service correctly.

  5. E

    The client wireless profile is incorrectly setup.

Show answer and explanation

Correct answer: B

Question 7 Single choice

An employee provisions a personal smart phone using the Onboard process. In addition, the employee has a corporate laptop provided by IT that connects to the secure network.

How many licenses does the employee consume?

  1. A

    1 Policy Manager license, 2 Guest Licenses

  2. B

    2 Policy Manager licenses, 1 Onboard License

  3. C

    1 Policy Manager license, 1 Onboard License

  4. D

    1 Policy Manager license, 1 Guest License

  5. E

    2 Policy Manager licenses, 2 Onboard Licenses

Show answer and explanation

Correct answer: B

Question 8 Single choice

Refer to the exhibit.

An employee connects a corporate laptop to the network and authenticates for the first time using EAP-
TLS.

Based on the Enforcement Policy configuration shown, which Enforcement Profile will be sent?

  1. A

    Onboard Post-Provisioning ?Aruba

  2. B

    Onboard Pre-Provisioning ?Aruba

  3. C

    Deny Access Profile

  4. D

    Onboard Device Repository

Show answer and explanation

Correct answer: A

Question 9 Multiple choice

Refer to the exhibit.

Which statements accurately describe the status of the Onboarded devices in the configuration for the network settings shown? (Select two.)

  1. A

    They will connect to Employee_Secure SSID after provisioning.

  2. B

    They will connect to Employee_Secure SSID for provisioning their devices.

  3. C

    They will use WPA2-PSK with AES when connecting to the SSID.

  4. D

    They will connect to secure_emp SSID after provisioning.

  5. E

    They will perform 802.1X authentication when connecting to the SSID.

Show answer and explanation

Correct answers: D, E

Question 10 Single choice

Why can the Onguard posture check not be performed during 802.1x authentication?

  1. A

    Health Checks cannot be used with 802.1x.

  2. B

    Onguard uses RADIUS, so an additional service must be created.

  3. C

    Onguard uses HTTPS, so an additional service must be created.

  4. D

    Onguard uses TACACS, so an additional service must be created.

  5. E

    802.1x is already secure, so Onguard is not needed.

Show answer and explanation

Correct answer: C

Explanation

OnGuard uses HTTPS to send posture information to the ClearPass appliance. For OnGuard to use HTTPS, it must have access to the network. If a customer requires 802.1x authentication on the wired switch, a separate 802.1x authentication must be used prior to the OnGuard posture check. In this example, an 802.1x PEAP-EAP-MSCHAPv2 authentication is completed first. A separate WebAuth service must be setup with posture checks to use the OnGuard agent.

References:
MAC Authentication and OnGuard Posture Enforcement using Dell WSeries ClearPass and
Dell Networking Switches (August 2013), page 21