Skip to main content

HPE6-A81 Real Exam Questions

Aruba Certified ClearPass Expert Written

60 questions available · Page 1 of 6

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Multiple choice

Refer to the exhibit:

You configured a new Wireless 802.1X service for a Cisco WLC broadcasting the Secure-ADM-5007 SSID. The client falls to connect to the SSID.
Using the screenshots as a reference, how would you fix this issue? (Select two.)

  1. A

    Update the service condition Radius:IETF Called-Station-ld CONTAINS secure-adm-5007

  2. B

    Make sure that the Network Devices entry for the Cisco WLC has a vendor setting of "Airspace"

  3. C

    Remove the service condition Radius:lETF Service-Type BELONGSJTO Login-User (1). 2. 8

  4. D

    Change the service condition to Radius:lETF Calling-Station-ld EQUALS Secure-ADM-5007

Show answer and explanation

Correct answers: A, C

Question 2 Single choice

When is it recommended to use a certificate with multiple entries on the Subject Alternative Name?

  1. A

    The ClearPass servers are placed in different OnGuard zones to allow the client agent to send SHV updates.

  2. B

    Using the same certificate to Onboard clients and the Guest Captive Portal on a single ClearPass server.

  3. C

    The primary authentication server Is not available to authenticate the users.

  4. D

    The ClearPass server will be hosting captive portal pages for multiple FQDN entries

Show answer and explanation

Correct answer: A

Question 3 Single choice

A customer has completed all the required configurations in the Windows server in order for Active Directory Certificate Services (ADCS) to sign Onboard device TLS certificates. The Onboard portal and the Onboard services are also configured. Testing shows that the Client certificates ate still signed by the Onboard Certificate Authority and not ADCS.

How can you help the customer with the situation?

  1. A

    Educate the customer that, when integrating with Active Directory Certificate Services (ADCS) the Onboard CA will the same authority used for signing me final TLS certificate of the device.

  2. B

    Configure the identity certificate signer as Active Directory Certificate Services and enter the ADCS URL http://ADCSVVeoEnrollmentServemostname/certsrv in the OnBoard Provisioning settings.

  3. C

    Enable access to EST servers from the Certificate Authority to make ClearPass Onboard to use of the Active Directory Certificate Services (ADCS) web enrollment to sign the device TLS certificates.

  4. D

    Enable access to SCEP servers from the Certificate Authority to make ClearPass Onboard to use of the Active Directory Certificate Services (ADCS) web enrollment to sign the device TLS certificates.

Show answer and explanation

Correct answer: C

Question 4 Single choice

What is the Open SSID (otherwise referred to as Dual SSID) Onboard deployment service workflow?

  1. A

    OnBoard Pre-Auth Application service, OnBoard Authorization Application service. OnBoard
    Provisioning RADIUS service

  2. B

    OnBoard Pre-Auth RADIUS service. OnBoard Authorization Application service. OnBoard Provisioning
    RADIUS service

  3. C

    OnBoard Authorization Application service, OnBoard Pre-Auth Application service, OnBoard

    Provisioning RADIUS service

  4. D

    OnBoard Authorization RADIUS service, OnBoard Pre-Auth Application service, OnBoard Provisioning
    RADIUS service

Show answer and explanation

Correct answer: C

Question 5 Single choice

Refer to the exhibit:

A customer is deploying Guest Self-Registration with Sponsor Approval but does not like the format of the sponsor email.

Where can you change the sponsor email?

  1. A

    in the Receipt Page - Actions

  2. B

    in the Sponsor Confirmation section

  3. C

    in me Configuration - Receipts - Email Receipts

  4. D

    in the Configuration - Receipts - Templates

Show answer and explanation

Correct answer: B

Question 6 Single choice

Refer to the exhibit:

A customer has configured a Guest Self registration page for their Cisco Wireless network with the settings shown.

What should be changed in order to successfully authenticate guests users?

  1. A

    Secure Login should use HTTP

  2. B

    Change the Vendor Settings to Airespace Networks

  3. C

    Change \he IP Address to the Cisco Controller DNS name

  4. D

    Login Method should be Controller-initiated - using HTTPs form submit

Show answer and explanation

Correct answer: C

Question 7 Single choice

Refer to the exhibit:

You have configured Onboard but me customer could not onboard one of his devices and has sent you the above screenshots.

How could you resolve the issue?

  1. A

    Instruct the user to delete the profile on one of their other BYOD devices.

  2. B

    Instruct the user to run the Quick connect application in Sponsor Mode.

  3. C

    Increase the maximum number of devices allowed by the individual user account.

  4. D

    Increase the maximum number of devices that all users can provision to 3.

Show answer and explanation

Correct answer: D

Question 8 Multiple choice

A customer is planning to implement machine and user authentication on infrastructure with one Aruba Controller and a single ClearPass Server.

What should the customer consider while designing this solution? (Select three.)

  1. A

    The Windows User must log off, restart or disconnect their machine to initiate a machine authentication before the cache expires.

  2. B

    The machine authentication status is written in the Multi-master cache on the ClearPass Server for 24 hrs.

  3. C

    Onboard must be used to install the Certificates on the personal devices to do the user and machine authentication.

  4. D

    The Customer should enable Multi-Master Cache Survivability as the Aruba Controller will not cache the machine state.

  5. E

    Machine Authentication only uses EAP TLS, as such a PKI infrastructure should be in place for machine authentication.

  6. F

    The customer does not need to worry about Multi-Master Cache Survivability because the Controller will also cache the machine state.

Show answer and explanation

Correct answers: B, C, E

Question 9 Multiple choice

A corporate ClearPass Cluster with two servers located at a single site, has both Management and Data port IP addresses configured. The Management port IPs are in the DataCenter networks subnet, while the Data port IPs are in the DMZ.

What is the difference between using one Virtual IP for the AAA traffic versus sending AAA requests to the physical IPs for each server? (Select two.)

  1. A

    The failover can be accomplished only by using Virtual IP.

  2. B

    The Individual IPs can provide failover and load balancing.

  3. C

    One Virtual IP can be used together with the individual server IPs for load balancing.

  4. D

    By using the Virtual IP, the failover convergence is faster than using individual server IPs.

  5. E

    Using the one Virtual IP can provide failover and load balancing.

Show answer and explanation

Correct answers: B, E

Question 10 Single choice

Refer to the exhibit:

A customer with multiple Aruba Controllers has just installed a new certificate for "*.customerdomain com" on all Aruba Controllers. While testing the existing guest Self-Registration page the customer noticed that the logins are failing. While troubleshooting they are finding no entries in the Event Viewer or Access Tracker for the tests. Suspecting that the Aruba Controllers may not be properly posting the credentials from the guest browser, they open the NAS Vendor Settings for the Guest Self-Registration Page.
From the screen shown, how can you fix the errors?

  1. A

    Change the "IP Address: field to" securelogin.customerdomain.com.

  2. B

    Change the "Secure Login:" field to "Use Vendor Default".

  3. C

    Change the "IP Address field to "captiveportal-login.customerdomain.com".

  4. D

    Add PTR records on the DNS server for "securelogin.arubanetworks.com".

Show answer and explanation

Correct answer: B