Skip to main content

HPE6-A78 Real Exam Questions

Aruba Certified Network Security Associate

167 questions available · Page 1 of 17

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

An AOS-CX switch currently has no device fingerprinting settings configured on it. You want the switch to start collecting DHCP and LLDP information. You enter these commands:

Switch(config)# client device-fingerprint profile myprofile
Switch(myprofile)# dhcp
Switch(myprofile)# lldp

What else must you do to allow the switch to collect information from clients?

  1. A

    Configure the switch as a DHCP relay

  2. B

    Add at least one LLDP option to the policy

  3. C

    Apply the policy to edge ports

  4. D

    Add at least one DHCP option to the policy

Show answer and explanation

Correct answer: C

Question 2 Single choice

You have configured a WLAN to use Enterprise security with the WPA3 version.

How does the WLAN handle encryption?

  1. A

    Traffic is encrypted with TKIP and keys derived from a PMK shared by all clients on the WLAN.

  2. B

    Traffic is encrypted with TKIP and keys derived from a unique PMK per client.

  3. C

    Traffic is encrypted with AES and keys derived from a PMK shared by all clients on the WLAN.

  4. D

    Traffic is encrypted with AES and keys derived from a unique PMK per client.

Show answer and explanation

Correct answer: D

Question 3 Single choice

What is a correct use case for using the specified certificate file format?

  1. A

    using a PKCS7 file to install a certificate plus and its private key on a device

  2. B

    using a PKCS12 file to install a certificate plus its private key on a device

  3. C

    using a PEM file to install a binary encoded certificate on a device

  4. D

    using a PKCS7 file to install a binary encoded private key on a device

Show answer and explanation

Correct answer: B

Question 4 Single choice

What does the NIST model for digital forensics define?

  1. A

    how to define access control policies that will properly protect a company's most sensitive data and digital resources

  2. B

    how to properly collect, examine, and analyze logs and other data, in order to use it as evidence in a security investigation

  3. C

    which types of architecture and security policies are best equipped to help companies establish a Zero Trust Network (ZTN)

  4. D

    which data encryption and authentication algorithms are suitable for enterprise networks in a world that is moving toward quantum computing

Show answer and explanation

Correct answer: B

Question 5 Multiple choice

You have detected a Rogue AP using the Security Dashboard

Which two actions should you take in responding to this event? (Select two)

  1. A

    There is no need to locale the AP If you manually contain It.

  2. B

    This is a serious security event, so you should always contain the AP immediately regardless of your
    company's specific policies.

  3. C

    You should receive permission before containing an AP. as this action could have legal Implications.

  4. D

    For forensic purposes, you should copy out logs with relevant information, such as the time mat the AP was detected and the AP's MAC address.

  5. E

    There is no need to locate the AP If the Aruba solution is properly configured to automatically contain it.

Show answer and explanation

Correct answers: C, D

Question 6 Single choice

What is one of the roles of the network access server (NAS) in the AAA framework?

  1. A

    It negotiates with each user's device to determine which EAP method is used for authentication.

  2. B

    It determines which resources authenticated users are allowed to access and monitors each user's session.

  3. C

    It enforces access to network services and sends accounting information to the AAA server.

  4. D

    It authenticates legitimate users and uses policies to determine which resources each user is allowed to access.

Show answer and explanation

Correct answer: C

Question 7 Single choice

Your HPE Aruba Networking Mobility Master-based solution has detected a rogue AP. Among other information, the AOS Detected Radios page lists this information for the AP:

SSID = PublicWiFi

BSSID = a8:bd:27:12:34:56

Match method = Plus one

Match method = Eth-Wired-Mac-Table The security team asks you to explain why this AP is classified as a rogue.

What should you explain?

  1. A

    The AP has been detected using multiple MAC addresses. This indicates that the AP is spoofing its MAC address, which qualifies it as a suspected rogue.

  2. B

    The AP is probably connected to your LAN because it has a BSSID that is close to a MAC address that has been detected in your LAN. Because it does not belong to the company, it is a suspected rogue.

  3. C

    The AP is an AP that belongs to your solution. However, the AOS has detected that it is behaving suspiciously. It might have been compromised, so it is classified as a suspected rogue.

  4. D

    The AP has a BSSID that is close to your authorized APs' BSSIDs. This indicates that the AP might be spoofing the corporate SSID and attempting to lure clients to it, making the AP a suspected rogue.

Show answer and explanation

Correct answer: B

Question 8 Single choice

How should admins deal with vulnerabilities that they find in their systems?

  1. A

    They should apply fixes, such as patches, to close the vulnerability before a hacker exploits it.

  2. B

    They should add the vulnerability to their Common Vulnerabilities and Exposures (CVE).

  3. C

    They should classify the vulnerability as malware. a DoS attack or a phishing attack.

  4. D

    They should notify the security team as soon as possible that the network has already been breached.

Show answer and explanation

Correct answer: A

Question 9 Single choice

What is one way a noneypot can be used to launch a man-in-the-middle (MITM) attack to wireless clients?

  1. A

    it uses a combination or software and hardware to jam the RF band and prevent the client from connecting to any wireless networks

  2. B

    it runs an NMap scan on the wireless client to And the clients MAC and IP address. The hacker then connects to another network and spoofs those addresses.

  3. C

    it examines wireless clients' probes and broadcasts the SSlDs in the probes, so that wireless clients will connect to it automatically.

  4. D

    it uses ARP poisoning to disconnect wireless clients from the legitimate wireless network and force clients to connect to the hacker's wireless network instead.

Show answer and explanation

Correct answer: C

Question 10 Single choice

You have deployed a new Aruba Mobility Controller (MC) and campus APs (CAPs). One of the WLANs
enforces 802.IX authentication lo Aruba ClearPass Policy Manager {CPPM) When you test connecting the
client to the WLAN. the test falls You check Aruba ClearPass Access Tracker and cannot find a record of the authentication attempt You ping from the MC to CPPM. and the ping is successful.

What is a good next step for troubleshooting?

  1. A

    Renew CPPM's RADIUS/EAP certificate

  2. B

    Reset the user credentials

  3. C

    Check CPPM Event viewer.

  4. D

    Check connectivity between CPPM and a backend directory server

Show answer and explanation

Correct answer: C