A customer would like to deploy ClearPass with these requirements: between 2000 to 3000 corporate users need to authenticate daily using EAP-TLS should allow for up to 1000 employee devices to be should allow up to 100 guest users each day to authenticate using the web login feature What is the license mix that customer will need to purchase?
-
A
CP-HW-2k, 1000 Onboard, 100 Guest
-
B
CP-HW-500, 1000 Onboard, 100 Guest
-
C
CP-HW-5k, 2500 Enterprise
-
D
CP-HW-5k, 1000 Enterprise
-
E
CP-HW-5k, 100 Onboard, 100 Guest
Reveal answer details
Close answer details
Question 2
Multiple choice
Refer to the exhibit.  Which statements accurately describe the status of the Onboarded devices in the configuration for the network settings shown? (Select two.)
-
A
They will connect to Employee_Secure SSID after provisioning.
-
B
They will connect to Employee_Secure SSID for provisioning their devices.
-
C
They will use WPA2-PSK with AES when connecting to the SSID.
-
D
They will connect to secure_emp SSID after provisioning.
-
E
They will perform 802.1X authentication when connecting to the SSID.
Reveal answer details
Close answer details
What does the Posture Token QUARANTINE imply?
-
A
The client is compliant. However, there is an update available to remediate the client to HEALTHY state.
-
B
The posture of the client is unknown.
-
C
The client is infected and is a threat to other systems in the network.
-
D
The client is out of compliance, but has HEALTHY state.
-
E
The client is out of compliance.
Reveal answer details
Close answer details
Question 4
Multiple choice
A hotel chain deployed ClearPass Guest. When hotel guests connect to the Guest SSID, launch a web browser and enter the address www.google.com, they are unable to immediately see the web login page. What are the likely causes of this? (Select two.)
-
A
The ClearPass server has a trusted server certificate issued by Verisign.
-
B
The ClearPass server has an untrusted server certificate issued by the internal Microsoft Certificate server.
-
C
The ClearPass server does not recognize the client's certificate.
-
D
The DNS server is not replying with an IP address for www.google.com.
Reveal answer details
Close answer details
Correct answersB, D
ExplanationYou would need a publicly signed certificate. References: http://community.arubanetworks.com/t5/Security/Clearpass-Guest-certificate-error-for-guest-visitors/td-p/221992
Question 5
Multiple choice
A customer wants all guests who access a company's guest network to have their accounts approved by the receptionist, before they are given access to the network. How should the network administrator set this up in ClearPass? (Select two.)
-
A
Enable sponsor approval confirmation in Receipt actions.
-
B
Configure SMTP messaging in the Policy Manager.
-
C
Configure a MAC caching service in the Policy Manager.
-
D
Configure a MAC auth service in the Policy Manager.
-
E
Enable sponsor approval in the captive portal authentication profile on the NAD.
Reveal answer details
Close answer details
Correct answersA, D
ExplanationA: Sponsored self-registration is a means to allow guests to self-register, but not give them full access until a sponsor (could even be a central help desk) has approved the request. When the registration form is completed by the guest/user, an on screen message is displayed for the guest stating the account requires approval. Guests are disabled upon registration and need to wait on the receipt page for the confirmation until the login button gets enabled. D. Device Mac Authentication is designed for authenticating guest devices based on their MAC address. References: ClearPass Policy Manager 6.5 User Guide (October 2015), page 94 (https://community.arubanetworks.com/aruba/attachments/aruba/SoftwareUserReferenceGuides/52/1/ClearPass%20Policy%20Manager%206.5%20User%20Guide.pdf)
Refer to the exhibit.  Based on the configuration of a Windows 802.1X supplicant shown, what will be the outcome when `Automatically use my Windows logon name and password' are selected?
-
A
The client will use machine authentication.
-
B
The client's Windows login username and password will be sent inside a certificate to the Active Directory server.
-
C
The client's Windows login username and password will be sent to the Authentication server.
-
D
The client will need to re-authenticate every time they connect to the network.
-
E
The client will prompt the user to enter the logon username and password.
Reveal answer details
Close answer details
Refer to the exhibit.  Based on the Aruba TACACS+ dictionary shown, how is the Aruba-Role attribute used?
-
A
The Aruba-Admin-Role on the controller is applies to users using TACACS+ to login to the Policy Manager
-
B
To assign different privileges to clients during 802.1X authentication
-
C
To assign different privileges to administrators logging into an Aruba NAD
-
D
It is used by ClearPass to assign TIPS roles to clients during 802.1X authentication
-
E
To assign different privileges to administrators logging into ClearPass
Reveal answer details
Close answer details
A client's authentication is failing and there are no entries in the ClearPass Access tracker. What is a possible reason for the authentication failure?
-
A
The user account has expired.
-
B
The client used a wrong password.
-
C
The shared secret between the NAD and ClearPass does not match.
-
D
The user's certificate is invalid.
-
E
The user is not found in the database.
Reveal answer details
Close answer details
Refer to the exhibit.  What does the Cache Timeout Value refer to?
-
A
The amount of time the Policy Manager caches the user credentials stored in the Active Directory.
-
B
The amount of time the Policy Manager waits for a response from the Active Directory before checking the backup authentication source.
-
C
The amount of time the Policy Manager caches the user attributes fetched from Active Directory.
-
D
The amount of time the Policy Manager waits for response from the Active Directory before sending a timeout message to the Network Access Device.
-
E
The amount of time the Policy Manager caches the user\s client certificate.
Reveal answer details
Close answer details
Question 10
Multiple choice
A customer wants to implement Virtual IP redundancy, such that in case of a ClearPass server outage, 802.1x authentications will not be interrupted. The administrator has enabled a single Virtual IP address on two ClearPass servers. Which statements accurately describe next steps? (Select two.)
-
A
The NAD should be configured with the primary node IP address for RADIUS authentication on the 802.1x network.
-
B
A new Virtual IP address should be created for each NAD.
-
C
Both the primary and secondary nodes will respond to authentication requests sent to the Virtual IP address when the primary node is active.
-
D
The primary node will respond to authentication requests sent to the Virtual IP address when the primary node is active.
-
E
The NAD should be configured with the Virtual IP address for RADIUS authentications on the 802.1x network.
Reveal answer details
Close answer details
Correct answersD, E
ExplanationIn an Aruba network, APs are controlled by a controller. The APs tunnel all data to the controller for processing, including encryption/decryption and bridging/forwarding data. Local controller redundancy provides APs with failover to a backup controller if a controller becomes unavailable. Local controller redundancy is provided by running VRRP between a pair of controllers. The APs are then configured to connect to the "virtual-IP" configured for the VRRP instance. References: http://www.arubanetworks.com/techdocs/ArubaOS_64x_WebHelp/Content/ArubaFrameStyles/VRRP/ Redundancy_Parameters.htm
Question 11
Single choice
Refer to the exhibit.  Based on the Policy configuration shown, which VLAN will be assigned when a user with ClearPass role Engineer authenticates to the network successfully using connection protocol WEBAUTH?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 12
Single choice
Refer to the exhibit.  Based on the information shown, which field in the Captive Portal Authentication profile should be changed so that guest users are redirected to a page on ClearPass when they connect to the Guest SSID?
-
A
both Login and Welcome Page
-
B
-
C
-
D
-
E
Reveal answer details
Close answer details
Correct answerE
ExplanationThe Login page is the URL of the page that appears for the user logon. This can be set to any URL. The Welcome page is the URL of the page that appears after logon and before redirection to the web URL. This can be set to any URL. References: http://www.arubanetworks.com/techdocs/ArubaOS_63_Web_Help/Content/ArubaFrameStyles/Captive_Portal/Captive_Portal_Authentic.htm
Question 13
Single choice
Refer to the exhibit.  Based on the network topology diagram shown, how many clusters are needed for this deployment?
-
A
-
B
-
C
-
D
-
E
Reveal answer details
Close answer details
Correct answerD
ExplanationReferences: http://www.arubanetworks.com/techdocs/ClearPass/Aruba_DeployGd_HTML/Content/5%20Cluster%20Deployment/Design_guidelines.htm
Question 14
Single choice
What is a benefit of ClearPass Onguard?
-
A
It enables organizations to run advanced endpoint posture assessments.
-
B
It allows a receptionist in a hotel to create accounts for guest users.
-
C
It allows employees to self-provision their personal devices on the corporate network.
-
D
It offers an easy way for users to self-configure their devices to support 802.1X authentication on wired and wireless networks.
-
E
It allows employees to create temporary accounts for Wi-Fi access.
Reveal answer details
Close answer details
Question 15
Multiple choice
A bank would like to deploy ClearPass Guest with web login authentication so that their customers can selfregister on the network to get network access when they have meetings with bank employees. However, they're concerned about security. What is true? (Choose three.)
-
A
If HTTPS is used for the web login page, after authentication is completed guest Internet traffic will all be encrypted as well.
-
B
During web login authentication, if HTTPS is used for the web login page, guest credentials will be encrypted.
-
C
After authentication, an IPSEC VPN on the guest's client be used to encrypt Internet traffic.
-
D
HTTPS should never be used for Web Login Page authentication.
-
E
If HTTPS is used for the web login page, after authentication is completed some guest Internet traffic may be unencrypted.
Reveal answer details
Close answer details
Question 16
Single choice
If the "Alerts" tab in an access tracker entry shows the following error message: "Access denied by policy", what could be a possible cause for authentication failure?
-
A
Configuration of the Enforcement Policy.
-
B
An error in the role mapping policy.
-
C
Failure to select an appropriate authentication method for the authentication request.
-
D
Implementation of a firewall policy on ClearPass.
-
E
Failure to find an appropriate service to process the authentication request.
Reveal answer details
Close answer details
Question 17
Multiple choice
In which ways can ClearPass derive client roles during policy service processing? (Select two.)
-
A
From the attributes configured in Active Directory
-
B
From the server derivation rule in the Aruba Controller server group for the client
-
C
From the Aruba Network Access Device
-
D
From the attributes configured in a Network Access Device
-
E
Through a role mapping policy
Reveal answer details
Close answer details
Question 18
Multiple choice
Which checks are made with Onguard posture evaluation in ClearPass? (Select three.)
-
A
-
B
EAP TLS certificate validity
-
C
-
D
Peer-to-peer application checks
-
E
Reveal answer details
Close answer details
|