You are configuring ArubaOS-CX switches to tunnel client traffic to an Aruba Mobility Controller (MC). What should you do to enhance security for control channel communications between the switches and the MC?
-
A
Create one UBT zone for control traffic and a second UBT zone for clients.
-
B
Configure a long, random PAPI security key that matches on the switches and the MC.
-
C
install certificates on the switches, and make sure that CPsec is enabled on the MC
-
D
Make sure that the UBT client vlan is assigned to the interface on which the switches reach the MC and only that interface.
Reveal answer details
Close answer details
What is a benefit of Protected Management Frames (PMF). sometimes called Management Frame Protection (MFP)?
-
A
PMF helps to protect APs and MCs from unauthorized management access by hackers.
-
B
PMF ensures trial traffic between APs and Mobility Controllers (MCs) is encrypted.
-
C
PMF prevents hackers from capturing the traffic between APs and Mobility Controllers.
-
D
PMF protects clients from DoS attacks based on forged de-authentication frames
Reveal answer details
Close answer details
Refer to the exhibit.  You are deploying a new ArubaOS Mobility Controller (MC), which is enforcing authentication to Aruba ClearPass Policy Manager (CPPM). The authentication is not working correctly, and you find the error shown In the exhibit in the CPPM Event Viewer. What should you check?
-
A
that the MC has been added as a domain machine on the Active Directory domain with which CPPM is synchronized
-
B
that the snared secret configured for the CPPM authentication server matches the one defined for the device on CPPM
-
C
that the IP address that the MC is using to reach CPPM matches the one defined for the device on CPPM
-
D
that the MC has valid admin credentials configured on it for logging into the CPPM
Reveal answer details
Close answer details
Question 4
Multiple choice
A company has AOS-CX switches deployed in a two-tier topology that uses OSPF routing at the core. You need to prevent ARP poisoning attacks. To meet this need, what is one technology that you could apply to user VLANs on access layer switches? (Select two.)
-
A
-
B
-
C
-
D
-
E
Reveal answer details
Close answer details
A company has an AOS controller-based solution with a WPA3-Enterprise WLAN, which authenticates wireless clients to HPE Aruba Networking ClearPass Policy Manager (CPPM). The company has decided to use digital certificates for authentication. A user's Windows domain computer has had certificates installed on it. However, the Networks and Connections window shows that authentication has failed for the user. The Mobility Controller's (MC's) RADIUS events show that it is receiving Access-Rejects for the authentication attempt. What is one place that you can look for deeper insight into why this authentication attempt is failing?
-
A
The reports generated by HPE Aruba Networking ClearPass Insight
-
B
The RADIUS events within the CPPM Event Viewer
-
C
The Alerts tab in the authentication record in CPPM Access Tracker
-
D
The packets captured on the MC control plane destined to UDP 1812
Reveal answer details
Close answer details
Refer to the exhibit.  A diem is connected to an ArubaOS Mobility Controller. The exhibit snows all Tour firewall rules that apply to this diem What correctly describes how the controller treats HTTPS packets to these two IP addresses, both of which are on the other side of the firewall: 10.1 10.10 203.0.13.5
-
A
It drops both of the packets
-
B
It permits the packet to 10.1.10.10 and drops the packet to 203 0.13.5
-
C
it permits both of the packets
-
D
It drops the packet to 10.1.10.10 and permits the packet to 203.0.13.5.
Reveal answer details
Close answer details
You have configured a WLAN to use Enterprise security with the WPA3 version. How does the WLAN handle encryption?
-
A
Traffic is encrypted with TKIP and keys derived from a PMK shared by all clients on the WLAN.
-
B
Traffic is encrypted with TKIP and keys derived from a unique PMK per client.
-
C
Traffic is encrypted with AES and keys derived from a PMK shared by all clients on the WLAN.
-
D
Traffic is encrypted with AES and keys derived from a unique PMK per client.
Reveal answer details
Close answer details
Refer to the exhibit.  This company has ArubaOS-Switches. The exhibit shows one access layer switch, Switch-2. as an example, but the campus actually has more switches. The company wants to slop any internal users from exploiting ARP What Is the proper way to configure the switches to meet these requirements?
-
A
On Switch-1, enable ARP protection globally, and enable ARP protection on ail VLANs.
-
B
On Switch-2, make ports connected to employee devices trusted ports for ARP protection
-
C
On Swltch-2, enable DHCP snooping globally and on VLAN 201 before enabling ARP protection
-
D
On Swltch-2, configure static PP-to-MAC bindings for all end-user devices on the network
Reveal answer details
Close answer details
What is one difference between EAP-Tunneled Layer Security (EAP-TLS) and Protected EAP (PEAP)?
-
A
EAP-TLS begins with the establishment of a TLS tunnel, but PEAP does not use a TLS tunnel as part of its process.
-
B
EAP-TLS requires the supplicant to authenticate with a certificate, but PEAP allows the supplicant to use a username and password.
-
C
EAP-TLS creates a TLS tunnel for transmitting user credentials, while PEAP authenticates the server and supplicant during a TLS handshake.
-
D
EAP-TLS creates a TLS tunnel for transmitting user credentials securely, while PEAP protects user credentials with TKIP encryption.
Reveal answer details
Close answer details
Question 10
Single choice
This company has AOS-CX switches. The exhibit shows one access layer switch, Switch-2, as an example, but the campus actually has more switches. Switch-1 is a core switch that acts as the default router for end-user devices.  What is a correct way to configure the switches to protect against exploits from untrusted end-user devices?
-
A
On Switch-1, enable ARP inspection on VLAN 100 and DHCP snooping on VLANs 15 and 25.
-
B
On Switch-2, enable DHCP snooping globally and on VLANs 15 and 25. Later, enable ARP inspection on the same VLANs.
-
C
On Switch-2, enable BPDU filtering on all edge ports in order to prevent eavesdropping attacks by untrusted devices.
-
D
On Switch-1, enable DHCP snooping on VLAN 100 and ARP inspection on VLANs 15 and 25.
Reveal answer details
Close answer details
Question 11
Single choice
What is a benefit of Opportunistic Wireless Encryption (OWE)?
-
A
It allows both WPA2-capable and WPA3-capable clients to authenticate to the same WPA-Personal WLAN.
-
B
It offers more control over who can connect to the wireless network when compared with WPA2- Personal.
-
C
It allows anyone to connect, but provides better protection against eavesdropping than a traditional open network.
-
D
It provides protection for wireless clients against both honeypot APs and man-in-the-middle (MITM) attacks.
Reveal answer details
Close answer details
Question 12
Single choice
What is one way that WPA3-PerSonal enhances security when compared to WPA2- Personal?
-
A
WPA3-Perscn3i is more secure against password leaking Because all users nave their own username and password
-
B
WPA3-Personai prevents eavesdropping on other users' wireless traffic by a user who knows the passphrase for the WLAN.
-
C
WPA3-Personai is more resistant to passphrase cracking Because it requires passphrases to be at least 12 characters
-
D
WPA3-Personal is more complicated to deploy because it requires a backend authentication server
Reveal answer details
Close answer details
Question 13
Single choice
What is a benefit or using network aliases in ArubaOS firewall policies?
-
A
You can associate a reputation score with the network alias to create rules that filler traffic based on reputation rather than IP.
-
B
You can use the aliases to translate client IP addresses to other IP addresses on the other side of the firewall
-
C
You can adjust the IP addresses in the aliases, and the rules using those aliases automatically update
-
D
You can use the aliases to conceal the true IP addresses of servers from potentially untrusted clients.
Reveal answer details
Close answer details
Question 14
Single choice
What are the roles of 802.1X authenticators and authentication servers?
-
A
The authenticator stores the user account database, while the server stores access policies.
-
B
The authenticator supports only EAP, while the authentication server supports only RADIUS.
-
C
The authenticator is a RADIUS client and the authentication server is a RADIUS server.
-
D
The authenticator makes access decisions and the server communicates them to the supplicant.
Reveal answer details
Close answer details
Question 15
Single choice
What is symmetric encryption?
-
A
It simultaneously creates ciphertext and a same-size MAC.
-
B
It any form of encryption mat ensures that thee ciphertext Is the same length as the plaintext.
-
C
It uses the same key to encrypt plaintext as to decrypt ciphertext.
-
D
It uses a Key that is double the size of the message which it encrypts.
Reveal answer details
Close answer details
Question 16
Single choice
A user attempts to connect to an SSID configured on an AOS-8 mobility architecture with Mobility Controllers (MCs) and APs. The SSID enforces WPA3-Enterprise security and uses HPE Aruba Networking ClearPass Policy Manager (CPPM) as the authentication server. The WLAN has initial role, logon, and 802.1X default role, guest. A user attempts to connect to the SSID, and CPPM sends an Access-Accept with an Aruba-User-Role VSA of "contractor," which exists on the MC. What does the MC do?
-
A
Applies the rules in the logon role, then guest role, and the contractor role
-
B
Applies the rules in the contractor role
-
C
Applies the rules in the contractor role and the logon role
-
D
Applies the rules in the contractor role and guest role
Reveal answer details
Close answer details
Question 17
Single choice
What is the purpose of an Enrollment over Secure Transport (EST) server?
-
A
It acts as an intermediate Certification Authority (CA) that signs end-entity certificates.
-
B
It helps admins to avoid expired certificates with less management effort.
-
C
It provides a secure central repository for private keys associated with devices' digital certif-icates.
-
D
It provides a more secure alternative to private CAs at less cost than a public CA.
Reveal answer details
Close answer details
Question 18
Single choice
Refer to the exhibit.  You are deploying a new HPE Aruba Networking Mobility Controller (MC), which is enforcing authentication to HPE Aruba Networking ClearPass Policy Manager (CPPM). The authentication is not working correctly, and you find the error shown in the exhibit in the CPPM Event Viewer. What should you check?
-
A
That the IP address that the MC is using to reach CPPM matches the one defined for the device on CPPM
-
B
That the MC has valid admin credentials configured on it for logging into the CPPM
-
C
That the MC has been added as a domain machine on the Active Directory domain with which CPPM is synchronized
-
D
That the shared secret configured for the CPPM authentication server matches the one defined for the device on CPPM
Reveal answer details
Close answer details
Question 19
Single choice
What is one of the roles of the network access server (NAS) in the AAA framewonx?
-
A
It authenticates legitimate users and uses policies to determine which resources each user is allowed to access.
-
B
It negotiates with each user's device to determine which EAP method is used for authentication
-
C
It enforces access to network services and sends accounting information to the AAA server
-
D
It determines which resources authenticated users are allowed to access and monitors each users session
Reveal answer details
Close answer details
Question 20
Single choice
A company has added a new user group. Users in the group try to connect to the WLAN and receive errors that the connection has no Internet access. The users cannot reach any resources. The first exhibit shows the record for one of the users who cannot connect. The second exhibit shows the role to which the ArubaOS device assigned the user's client. What is a likely problem?
-
A
The ArubaOS device has a server derivation rule configured on it that has overridden the role sent by CPPM.
-
B
The ArubaOS device does not have the correct RADIUS dictionaries installed on it to under-stand the Aruba-User-Role VSA.
-
C
The role name that CPPM is sending does not match the role name configured on the Aru-baOS device.
-
D
The clients rejected the server authentication on their side because they do not have the root CA for CPPM's RADIUS/EAP certificate.
Reveal answer details
Close answer details
Question 21
Single choice
You have a network with AOS-CX switches for which HPE Aruba Networking ClearPass Policy Manager (CPPM) acts as the TACACS+ server. When an admin authenticates, CPPM sends a response with: Aruba-Priv-Admin-User = 1 TACACS+ privilege level = 15 What happens to the user?
-
A
The user receives auditors access.
-
B
The user receives no access.
-
C
The user receives administrators access.
-
D
The user receives operators access.
Reveal answer details
Close answer details
Question 22
Single choice
A company has an ArubaOS solution. The company wants to prevent users assigned to the "user_group1" role from using gaming and peer-to-peer applications. What is the recommended approach for these requirements?
-
A
Make sure DPI is enabled, and add application rules that deny gaming and peer-to-peer applications to the "user_groupr role.
-
B
Create ALGs for the gaming and peer-to-peer applications, and deny the "user_group1" role on the ALGs.
-
C
Add access control rules to the "user_group1" role, which deny HTTP/HTTPS traffic to IP addresses associated with gaming and peer-to-peer applications.
-
D
Create service aliases for the TCP ports associated with gaming and peer-to-per applications, and use those aliases in access control rules for the "user_group" rules.
Reveal answer details
Close answer details
Question 23
Single choice
Refer to the exhibit, which shows the current network topology.  You are deploying a new wireless solution with an Aruba Mobility Master (MM). Aruba Mobility Controllers (MCs). and campus APs (CAPs). The solution will Include a WLAN that uses Tunnel for the forwarding mode and Implements WPA3-Enterprise security What is a guideline for setting up the vlan for wireless devices connected to the WLAN?
-
A
Assign the WLAN to a single new VLAN which is dedicated to wireless users
-
B
Use wireless user roles to assign the devices to different VLANs in the 100-150 range
-
C
Assign the WLAN to a named VLAN which specified 100-150 as the range of IDs.
-
D
Use wireless user roles to assign the devices to a range of new vlan IDs.
Reveal answer details
Close answer details
Question 24
Single choice
An ArubaOS-CX switch enforces 802.1X on a port. No fan-through options or port-access roles are configured on the port The 802 1X supplicant on a connected client has not yet completed authentication Which type of traffic does the authenticator accept from the client?
-
A
-
B
DHCP, DNS and RADIUS only
-
C
-
D
Reveal answer details
Close answer details
Question 25
Single choice
What is one way that Control Plane Security (CPSec) enhances security for the network?
-
A
It protects management traffic between APs and Mobility Controllers (MCs) from eavesdropping.
-
B
It prevents Denial of Service (DoS) attacks against Mobility Controllers' (MCs') control plane.
-
C
It protects wireless clients' traffic, tunneled between APs and Mobility Controllers, from eavesdropping.
-
D
It prevents access from unauthorized IP addresses to critical services, such as SSH, on Mobility Controllers (MCs).
Reveal answer details
Close answer details
Question 26
Single choice
A customer has an AOS-10 network infrastructure. The customer is looking for a solution that can classify many different types of devices, including IoT devices. Which solution should you explain can provide these capabilities?
-
A
HPE Aruba Networking EdgeConnect SD-WAN
-
B
HPE Aruba Networking ClearPass OnGuard
-
C
HPE Aruba Networking Central
-
D
HPE Aruba Networking ClearPass Onboard
Reveal answer details
Close answer details
|