Preview real exam questions, verified answers and available explanations before choosing a study plan.
Question 1
Single choice
Refer to Exhibit:
With Access-1,
What needs to be identically configured With MSTP to load-balance VLANS?
A
Spanning-tree bpdu-guard setting
B
Spanning-tree instance vlan mapppjng
C
spanning-tree Cist mapping
D
Spanning-tree root-guard setting
Reveal answer detailsClose answer details
Correct answerB
Explanation
The correct answer is B. Spanning-tree instance VLAN mapping. To load-balance VLANs with MSTP, you need to configure the same VLAN-to-instance mapping on all switches in the same MST region. This means that you need to assign different VLANs to different MST instances, and then adjust the spanning tree parameters (such as priority, cost, or port role) for each instance to achieve the desired load balancing. For example, you can make one switch the root for instance 1 and another switch the root for instance 2, and then map half of the VLANs to instance 1 and the other half to instance 2. According to the Cisco document Understand the Multiple Spanning Tree Protocol (802.1s), one of the steps to configure MST is: Split your set of VLANs into more instances and configure different MST settings for each of these instances. In order to easily achieve this, elect Bridge D1 to be the root for VLANs 501 through 1000, and Bridge D2 to be the root for VLANs 1 through 500. These statements are true for this configuration: Switch D1(config)#spanning-tree mst configuration Switch D1(config-mst)#instance 1 vlan 501-1000 Switch D1(config-mst)#exit Switch D1(config)#spanning-tree mst 1 priority 0
Switch D2(config)#spanning-tree mst configuration Switch D2(config-mst)#instance 2 vlan 1-500 Switch D2(config-mst)#exit Switch D2(config)#spanning-tree mst 2 priority 0 The above commands create two MST instances, 1 and 2, and map VLANs 501-1000 to instance 1 and VLANs 1-500 to instance 2. Then, they make switch D1 the root for instance 1 and switch D2 the root for instance 2. The other options are incorrect because: A. Spanning-tree bpdu-guard setting is a security feature that disables a port if it receives a BPDU from an unauthorized device. It does not affect load balancing with MSTP. C. Spanning-tree CIST mapping is not a valid command. CIST stands for Common and Internal Spanning Tree, which is the spanning tree instance that runs within an MST region and interacts with other regions or non-MST switches. D. Spanning-tree root-guard setting is another security feature that prevents a port from becoming a root port if it receives superior BPDUs from another switch. It does not affect load balancing with MSTP.
Question 2
Single choice
A customer has a site with 200 AP-515 access points 75AP-565 access points installed. The customer is rolling out new mobile phones with Wi-Fi-calling.
802.1X is in use for authentication What should be enabled to ensure the best roaming experience?
Wi-Fi calling is a feature that allows you to make or receive voice calls over Wi-Fi instead of cellular network. Wi-Fi calling can provide better voice quality and reliability in areas with poor or no cellular coverage.
Question 3
Single choice
Your customer has asked you to assign a switch management role for a new user The customer requires the user role to only have Web Ul access to the System > Log page and only have access to the GET method for REST API for the /logs/event resource
Which default AOS-CX user role meets these requirements?
A
administrators
B
auditors
C
sysops
D
operators
Reveal answer detailsClose answer details
Correct answerA
Explanation
The auditors role is the default AOS-CX user role that meets the requirements of having Web UI access to the System > Log page and having access to the GET method for REST API for the /logs/event resource. The auditors role has a level of 1 and allows read-only access to most commands except those related to security or passwords. It also allows access to the Web UI and REST API with limited permissions. The other options are incorrect because they either have higher levels of access or do not allow access to the Web UI or REST API. References: https://www.arubanetworks.com/techdocs/AOS-CX/10.04/HTML/5200-6728/bk01- ch01.html (https://www.arubanetworks.com/techdocs/AOS-CX/10.04/HTML/5200-6728/bk01-ch04.html)
Question 4
Single choice
With the Aruba CX switch configuration, what is the Active Gateway feature that is used for and is unique to VSX configuration?
A
Sixteen different VMACs are supported total as shared.
B
Active Gateway can once MSTP instances are created for VLAN load sharing.
C
Sixteen different VMACS are supported for each IPV4 and IPV6 stack simultaneously
D
copied over the ISL link for an optimized path.
Reveal answer detailsClose answer details
Correct answerC
Explanation
The active gateway feature is used to provide active-active layer 3 default gateway for hosts on the same subnet. It allows the switch to convert multicast streams into unicast streams over the wireless link, which improves the quality and reliability of streaming video, while preserving the bandwidth available to the non-video clients. The active gateway feature is unique to VSX configuration because it eliminates the need for VRRP and avoids traffic being pushed over the ISL link, which can cause latency in the network 12. The correct answer to the question is C. Sixteen different VMACs are supported for each IPv4 and IPv6 stack simultaneously. This means that you can have a maximum of eight VMACs for IPv4, and a maximum of eight VMACs for IPv6, on a VSX pair. Only 15 VMACs are supported on 6400 switch series 2. The other options are incorrect because: A. Sixteen different VMACs are not supported total as shared. They are supported for each IPv4 and IPv6 stack separately. B. Active gateway can be used without MSTP instances. MSTP is a protocol that allows multiple spanning tree instances to coexist on the same switch, but it does not affect how active gateway works. D. Active gateway does not copy traffic over the ISL link for an optimized path. It avoids using the ISL link for routed traffic and uses the local switch interface MAC instead of the virtual MAC address (VMAC) for source address 1.
Question 5
Single choice
Your customer currently has Iwo (2) 5406 modular switches with MSTP configured as their core switches. You are proposing a new solution.
What would you explain regarding the Aruba CX VSX switch pair when the Primary VSX node is replaced and the system MAC is replaced?
A
VSX will select the MAC address from a node that is the lower ID.
B
Configure vMAC on the Primary VSX node under VSX to retain MAC after hardware replacement.
C
VSX will select the MAC address from a node that is a higher ID.
D
During the initial VSX configuration, the system-mac is assigned with a fixed MAC based on VSX ID.
Reveal answer detailsClose answer details
Correct answerD
Explanation
The system-mac command is used to configure a fixed MAC address for the VSX system. This MAC address is used as the source MAC address for all routed traffic from the VSX node. The system-mac command is highly recommended for preventing traffic disruptions when the primary VSX switch restores after the secondary VSX switch, such as during a primary switch hardware replacement or a power outage 2. During the initial VSX configuration, the system-mac is assigned with a fixed MAC based on VSX ID. The system-mac command can be used to change this default MAC address if needed 2. Therefore, answer D is correct. References: 1: Aruba Campus Access documents and learning resources 2: system-mac - Aruba
Question 6
Single choice
You are proposing new CX 8360 VSX switches to replace a customer's existing core switches.
The customer is concerned about the possibility of a split-brain scenario between the VSX pair.
How is the VSX pair affected when the ISL is down and keepalive is up?
A
The VSX pair is out-of-sync.
B
The VSX pair nodes are still forwarding traffic.
C
The VSX LAGs are in a degraded state.
D
The VSX pair is not at risk.
Reveal answer detailsClose answer details
Correct answerD
Question 7
Single choice
A WLAN architect is reviewing roaming standards. The requirement is to let APs and clients exchange radio measurement information that can help clients make better roaming choices.
Which standard addresses this requirement?
A
802.11k
B
802.11r
C
802.11w
D
802.3at
Reveal answer detailsClose answer details
Correct answerA
Explanation
802.11k is the correct answer because it defines radio resource measurement mechanisms that help clients learn more about the surrounding RF environment, including neighbor-related information. This can improve roaming efficiency by giving the client more useful data when selecting a candidate AP. 802.11r is focused on fast transition keying and reduced reauthentication delay. 802.11w protects management frames, and 802.3at is a PoE standard unrelated to WLAN roaming intelligence.
Question 8
Single choice
An AOS 10 deployment uses APs that authenticate clients against a cloud-based RADIUS service. The customer wants the RADIUS conversation protected in transit between the APs and the RADIUS server.
Which solution should be used?
A
Configure EAP-TLS on all clients only
B
Use RadSec between the APs and the RADIUS server
C
Enable GRE between APs and gateways
D
Change the SSID to WPA3-Personal
Reveal answer detailsClose answer details
Correct answerB
Explanation
RadSec is the right answer because it protects RADIUS traffic by carrying it over TLS, providing confidentiality and server authentication for the AAA exchange path. This addresses the stated concern about exposure between the AP and the cloud-based RADIUS service. EAP-TLS strengthens client authentication but does not itself secure the RADIUS transport hop in the same way. GRE is a tunneling technology unrelated to RADIUS protection, and WPA3-Personal changes the client access method rather than securing the AP-to-RADIUS transport.
Question 9
Single choice
Which network components communicate using the RADIUS protocol for authentication and accounting?
A
an access point and the endpoint device
B
a Network Access Server and a RADIUS authentication server
C
an endpoint device and a RADIUS authentication server
D
a Network Access Server and an endpoint device
Reveal answer detailsClose answer details
Correct answerB
Question 10
Single choice
In an AOS-10 architecture using an AP, a gateway and traffic forwarding mode * mixed, what happens when a client connects to an open enhanced 5SID where their VLAN assignment will be bridged?
A
Authenticated Diffie-Hellman is not utilized
B
RADIUS protocol is utilized.
C
No encryption is applied.
D
The gateway will not respond.
Reveal answer detailsClose answer details
Correct answerA
Question 11
Single choice
Your customer has an Aruba CX 6200F VSF stack with two switches. A third member (JL726A) needs to be added to the VSF configuration.
What e the configuration that enables the new devices to join the VSF?
A
Option A
B
Option B
C
Option C
D
Option D
Reveal answer detailsClose answer details
Correct answerC
Explanation
According to the Aruba Documentation Portal1, the Aruba CX 6200F VSF stack is a feature that allows you to create a virtual switching framework (VSF) with up to eight members that can be managed as a single logical device. The VSF stack provides benefits such as load balancing, failover, redundancy, and security. To add a new device to the VSF stack, you need to configure the device with the VSF command vsf member and specify the type, link, and secondary-member information. The type of the new device can be one of the following: JL726A, JL726B, JL726C, or JL726D. The link is the interface that connects the new device to the existing VSF members. The secondary-member is an optional parameter that specifies which member will act as a backup in case of a failure. 1: https://www.arubanetworks.com/techdocs/AOS-CX/10.06/HTML/5200-7726/index.html 2: https://buy.hpe.com/us/en/networking/switches/fixed-port-l3-managed-ethernet-switches/6000-switch-products/aruba-6200f-48g-4sfp-switch/p/jl726a3: https://addin.co.th/shop/switch/aruba-switch/6200f-series/jl726a/
Question 12
Drag & drop
DRAG DROP
List the firewall role derivation flow in the correct order.
Reveal answer detailsClose answer details
Explanation
According to the Aruba Documentation Portal1, the firewall role derivation flow in the correct order is: Server derived role User derived role Authentication default role Initiation role assigned
Question 13
Single choice
You must ensure the HPEAruba network you are configuring for a client is capable of plug-and-play provisioning of access points.
What enables this capability?
A
UCC Service
B
LLDP-MED
C
SRTP
D
CSMA
Reveal answer detailsClose answer details
Correct answerA
Explanation
The capability that enables plug-and-play provisioning of access points in an HPE Aruba network is the UCC Service. The UCC Service is a cloud-based service that allows the access points to automatically discover and connect to the Aruba Central management platform without any manual intervention. The UCC Service also provides zero-touch configuration, firmware updates, and monitoring for the access points 1. The other options are incorrect because: B. LLDP-MED: LLDP-MED is a protocol that enhances the interoperability between network devices and IP phones. It does not enable plug-and-play provisioning of access points 2. C. SRTP: SRTP is a protocol that provides encryption and authentication for voice and video traffic. It does not enable plug-and-play provisioning of access points 3. D. CSMA: CSMA is a protocol that regulates how devices share a common medium, such as a wireless channel. It does not enable plug-and-play provisioning of access points.
Question 14
Single choice
When setting up an AOS-CX VSX pair, which information does the Inter-Switch Link Protocol configuration use in the configuration created?
A
dead interval is disabled by default
B
dead interval is based on the value set for hello interval
C
dead interval is 200ms by default
D
dead interval is 20s by default
Reveal answer detailsClose answer details
Correct answerD
Question 15
Single choice
In an ArubaOS 10 architecture using an AP and a gateway, what happens when a client attempts to join the network and the WLAN is configured with OWE?
A
Authentication information is not exchanged
B
The Gateway will not respond.
C
No encryption is applied.
D
RADIUS protocol is utilized.
Reveal answer detailsClose answer details
Correct answerA
Explanation
This is the correct statement about what happens when a client attempts to join the network and the WLAN is configured with OWE (Opportunistic Wireless Encryption). OWE is a standard that provides encryption for open networks without requiring any authentication or credentials from the client or the network. OWE uses a Diffie-Hellman key exchange mechanism to establish a secure session between the client and the AP without exchanging any authentication information. The other options are incorrect because they either describe scenarios that require authentication or encryption methods that are not used by OWE. References: https://www.arubanetworks.com/assets/wp/WP_WiFi6.pdf https://www.arubanetworks.com/assets/ds/ DS_AP510Series.pdf
Question 16
Single choice
When setting up an Aruba CX VSX pair, which information does the Inter-Switch Link Protocol configuration use in the configuration created?
A
QSVI
B
MAC tables
C
UDLD
D
RPVST+
Reveal answer detailsClose answer details
Correct answerB
Explanation
The information that the Inter-Switch Link Protocol configuration uses in the configuration created is B. MAC tables. The Inter-Switch Link Protocol (ISL) is a protocol that enables the synchronization of data and state information between two VSX peer switches. The ISL uses a version control mechanism and provides backward compatibility regarding VSX synchronization capabilities. The ISL can span long distances (transceiver dependent) and supports different speeds, such as 10G, 25G, 40G, or 100G1. One of the data components that the ISL synchronizes is the MAC table, which is a database that stores the MAC addresses of the devices connected to the switch and the corresponding ports or VLANs. The ISL ensures that both VSX peers have the same MAC table entries and can forward traffic to the correct destination 2. The ISL also synchronizes other data components, such as ARP table, LACP states for VSX LAGs, and MSTP states 2.
Question 17
Single choice
Refer to the exhibit.
With Core-1. what is the default value for config-revision?
A
0
B
1
C
1-0
D
0. 0
Reveal answer detailsClose answer details
Correct answerA
Explanation
The default value for config-revision on Core-1 is 0. Config-revision is a parameter that indicates the configuration version of a VSX pair. It is used to synchronize the configuration between the VSX peers and to detect any configuration mismatch. The config-revision value is set to 0 by default on both VSX peers and is incremented by 1 every time a configuration change is made on either peer. The other options are incorrect because they do not reflect the default value of config-revision. References: https://www.arubanetworks.com/techdocs/AOS-CX/10.04/HTML/5200-6728/bk01- ch07.html (https://www.arubanetworks.com/techdocs/AOS-CX/10.04/HTML/5200-6728/bk01-ch02.html)
Question 18
Multiple choice
A customer is looking Tor a wireless authentication solution for all of their loT devices that meet the following requirements
1. The wireless traffic between the IoT devices and the Access Points must be encrypted 2. Unique passphrase per device 3. Use fingerprint information to perform role-based access
Which solutions will address the customer's requirements? (Select two.)
A
MPSK and an internal RADIUS server
B
MPSK Local with MAC Authentication
C
ClearPass Policy Manager
D
MPSK Local with EAP-TLS
E
Local User Derivation Rules
Reveal answer detailsClose answer details
Correct answersC, D
Explanation
The correct answers are C and D. MPSK (Multi Pre-Shared Key) is a feature that allows multiple PSKs to be used on a single SSID, providing device-specific or group-specific passphrases for enhanced security and deployment flexibility for headless IoT devices 1. MPSK requires MAC authentication against a ClearPass Policy Manager server, which returns the encrypted passphrase for the device in a RADIUS VSA2. ClearPass Policy Manager is a platform that provides role-and device-based network access control for any user across any wired, wireless and VPN infrastructure 3. ClearPass Policy Manager can also use device profiling and posture assessment to assign roles based on device fingerprint information 4. MPSK Local is a variant of MPSK that allows the user to configure up to 24 PSKs per SSID locally on the device, without requiring ClearPass Policy Manager5. MPSK Local can be combined with EAP-TLS (Extensible Authentication Protocol- Transport Layer Security), which is a secure authentication method that uses certificates to encrypt the wireless traffic between the IoT devices and the access points 6. EAP-TLS can also use device certificates to perform role-based access control 6. Therefore, both ClearPass Policy Manager and MPSK Local with EAP-TLS can meet the customer's requirements for wireless authentication, encryption, unique passphrase, and role-based access for their IoT devices. MPSK and an internal RADIUS server is not a valid solution, because MPSK does not support internal RADIUS servers and requires ClearPass Policy Manager789. MPSK Local with MAC Authentication is not a valid solution, because MAC Authentication does not encrypt the wireless traffic or use fingerprint information for role-based access 2. Local User Derivation Rules are not a valid solution, because they do not provide unique passphrase per device or use fingerprint information for role-based access101112.
Question 19
Single choice
What is used to retrieve data stored in a Management Information Base (MIS)?
A
SNMPv3
B
DSCP
C
TLV
D
CDP
Reveal answer detailsClose answer details
Correct answerA
Explanation
The correct answer is A. SNMPv3. SNMPv3 is a protocol that is used to retrieve data stored in a Management Information Base (MIB), which is a database of managed objects in a network. SNMPv3 provides security and access control features that are not available in earlier versions of SNMP. SNMPv3 can also use encryption to protect the data from unauthorized access or modification. According to the Aruba Certified Professional ?Campus Access document1, one of the skills that this certification validates is: Implement and Analyze the output from common network monitoring tools The document also mentions that the candidate should have a distinguished understanding of different protocols across vendors, which implies that they should be familiar with SNMPv3 and how it can be used to access MIB data.
Question 20
Single choice
An administrator is creating a guest SSID that must encrypt user traffic but must not require credentials or 802.1X authentication.
Which wireless security method should the administrator select?
A
WPA3-Personal
B
WPA3-Enterprise
C
OWE
D
Open with captive portal only
Reveal answer detailsClose answer details
Correct answerC
Explanation
OWE, also called Enhanced Open in many Aruba workflows, is intended for situations where encryption is required but user authentication is not. It protects traffic on an otherwise open network by establishing encryption without using a shared password or 802.1X. WPA3-Personal requires a passphrase, and WPA3-Enterprise requires 802.1X with a RADIUS-based authentication workflow. A purely open network with captive portal does not provide over-the-air encryption before portal interaction.
Question 21
Multiple choice
You are configuring Policy Based Routing (PBR) for a subnet that will be used to test a new default route for your network Traffic originating from 10.2.250.0/24 should use a new default route to 10.1.1.253. Other non-default routes for this subnet should not be affected by this change.
What are two parts of the solution for these requirements? (Select two.)
A
Option A
B
Option B
C
Option C
D
Option D
E
Option E
Reveal answer detailsClose answer details
Correct answersC, E
Explanation
Two parts of the solution for these requirements are Option C and Option E. Option C is a part of the solution because it defines a policy-based routing action list named route_test, which specifies the next hop IP address as 10.1.1.253 for the matching traffic. This is the new default route that the user wants to use for the subnet 10.2.250.0/24. The interface null parameter indicates that the traffic will be routed to the next hop without using a specific interface 1. Option E is a part of the solution because it applies the policy-based routing action list route_test to the VLAN interface 250, which has an IP address of 10.2.250.1/24. This is the subnet that the user wants to test the new default route for. The apply policy command enables policy-based routing on the interface and associates it with the action list 2. Option A is not a part of the solution because it defines a policy-based routing action list named route_test, but does not specify the next hop IP address as 10.1.1.253, which is the new default route that the user wants to use. Instead, it specifies a next hop IP address of 10.1.1.254, which is different from the requirement. Option B is not a part of the solution because it defines a policy-based routing action list named route_test, but does not specify any next hop IP address at all, which is necessary for policy-based routing to work. Instead, it specifies an interface null parameter without any IP address, which is invalid. Option D is not a part of the solution because it applies the policy-based routing action list route_test to the VLAN interface 200, which has an IP address of 10.2.200.1/24. This is not the subnet that the user wants to test the new default route for, but a different subnet that should not be affected by this change.
Question 22
Single choice
You are setting up a customer's 150 headless loT devices that do not support 802.1 X.
What should you use?
A
Multiple Pre-Shared Keys (MPSK) Local
B
Multiple Pre-Shared Keys (MPSK) with WPA3-AES
C
HPE Aruba Networking ClearPass profiling with MAC-AUTH
D
HPE Aruba Networking ClearPass profiling with WPA-PSK
Reveal answer detailsClose answer details
Correct answerA
Question 23
Single choice
A customer wants to improve guest user experience because devices that wake from sleep are repeatedly redirected to the captive portal splash page.
What should be enabled?
A
MAC caching on the splash page workflow
B
Dynamic authorization on the switch
C
OSPF graceful restart
D
Port mirroring on uplinks
Reveal answer detailsClose answer details
Correct answerA
Explanation
MAC caching is the correct feature because it allows returning guest devices to be recognized by their MAC address after the initial successful portal interaction, reducing the need to present the splash page repeatedly. This is a common user-experience improvement for guest access environments where devices often sleep and reconnect. Dynamic authorization is an AAA policy-change mechanism, not a guest portal convenience feature. OSPF graceful restart and port mirroring are unrelated to captive portal behavior.
Question 24
Single choice
With the CX 6000 48G switch with uplinks of 1/1/47 and 1/1/48, what does the switch do when a client port detects a loop and tx-disable parameter is used?
A
The ports that confirmed the loop are disabled.
B
The ports that transmitted and received the loop are disabled.
What needs to be identically configured With MSTP to load-balance VLANS?
A.
Spanning-tree bpdu-guard setting
B.
Spanning-tree instance vlan mapppjng
C.
spanning-tree Cist mapping
D.
Spanning-tree root-guard setting
Correct Answer: B
Explanation
Explanation/Reference:
The correct answer is B. Spanning-tree instance VLAN mapping. To load-balance VLANs with MSTP, you need to configure the same VLAN-to-instance mapping on all switches in the same MST region. This means that you need to assign different VLANs to different MST instances, and then adjust the spanning tree parameters (such as priority, cost, or port role) for each instance to achieve the desired load balancing. For example, you can make one switch the root for instance 1 and another switch the root for instance 2, and then map half of the VLANs to instance 1 and the other half to instance 2. According to the Cisco document Understand the Multiple Spanning Tree Protocol (802.1s), one of the steps to configure MST is: Split your set of VLANs into more instances and configure different MST settings for each of these instances. In order to easily achieve this, elect Bridge D1 to be the root for VLANs 501 through 1000, and Bridge D2 to be the root for VLANs 1 through 500. These statements are true for this configuration: Switch D1(config)#spanning-tree mst configuration Switch D1(config-mst)#instance 1 vlan 501-1000 Switch D1(config-mst)#exit Switch D1(config)#spanning-tree mst 1 priority 0
Switch D2(config)#spanning-tree mst configuration Switch D2(config-mst)#instance 2 vlan 1-500 Switch D2(config-mst)#exit Switch D2(config)#spanning-tree mst 2 priority 0 The above commands create two MST instances, 1 and 2, and map VLANs 501-1000 to instance 1 and VLANs 1-500 to instance 2. Then, they make switch D1 the root for instance 1 and switch D2 the root for instance 2. The other options are incorrect because: A. Spanning-tree bpdu-guard setting is a security feature that disables a port if it receives a BPDU from an unauthorized device. It does not affect load balancing with MSTP. C. Spanning-tree CIST mapping is not a valid command. CIST stands for Common and Internal Spanning Tree, which is the spanning tree instance that runs within an MST region and interacts with other regions or non-MST switches. D. Spanning-tree root-guard setting is another security feature that prevents a port from becoming a root port if it receives superior BPDUs from another switch. It does not affect load balancing with MSTP.
QUESTION 2
A customer has a site with 200 AP-515 access points 75AP-565 access points installed. The customer is rolling out new mobile phones with Wi-Fi-calling.
802.1X is in use for authentication What should be enabled to ensure the best roaming experience?
Wi-Fi calling is a feature that allows you to make or receive voice calls over Wi-Fi instead of cellular network. Wi-Fi calling can provide better voice quality and reliability in areas with poor or no cellular coverage.
QUESTION 3
Your customer has asked you to assign a switch management role for a new user The customer requires the user role to only have Web Ul access to the System > Log page and only have access to the GET method for REST API for the /logs/event resource
Which default AOS-CX user role meets these requirements?
A.
administrators
B.
auditors
C.
sysops
D.
operators
Correct Answer: A
Explanation
Explanation/Reference:
The auditors role is the default AOS-CX user role that meets the requirements of having Web UI access to the System > Log page and having access to the GET method for REST API for the /logs/event resource. The auditors role has a level of 1 and allows read-only access to most commands except those related to security or passwords. It also allows access to the Web UI and REST API with limited permissions. The other options are incorrect because they either have higher levels of access or do not allow access to the Web UI or REST API. References: https://www.arubanetworks.com/techdocs/AOS-CX/10.04/HTML/5200-6728/bk01- ch01.html (https://www.arubanetworks.com/techdocs/AOS-CX/10.04/HTML/5200-6728/bk01-ch04.html)
QUESTION 4
With the Aruba CX switch configuration, what is the Active Gateway feature that is used for and is unique to VSX configuration?
A.
Sixteen different VMACs are supported total as shared.
B.
Active Gateway can once MSTP instances are created for VLAN load sharing.
C.
Sixteen different VMACS are supported for each IPV4 and IPV6 stack simultaneously
D.
copied over the ISL link for an optimized path.
Correct Answer: C
Explanation
Explanation/Reference:
The active gateway feature is used to provide active-active layer 3 default gateway for hosts on the same subnet. It allows the switch to convert multicast streams into unicast streams over the wireless link, which improves the quality and reliability of streaming video, while preserving the bandwidth available to the non-video clients. The active gateway feature is unique to VSX configuration because it eliminates the need for VRRP and avoids traffic being pushed over the ISL link, which can cause latency in the network 12. The correct answer to the question is C. Sixteen different VMACs are supported for each IPv4 and IPv6 stack simultaneously. This means that you can have a maximum of eight VMACs for IPv4, and a maximum of eight VMACs for IPv6, on a VSX pair. Only 15 VMACs are supported on 6400 switch series 2. The other options are incorrect because: A. Sixteen different VMACs are not supported total as shared. They are supported for each IPv4 and IPv6 stack separately. B. Active gateway can be used without MSTP instances. MSTP is a protocol that allows multiple spanning tree instances to coexist on the same switch, but it does not affect how active gateway works. D. Active gateway does not copy traffic over the ISL link for an optimized path. It avoids using the ISL link for routed traffic and uses the local switch interface MAC instead of the virtual MAC address (VMAC) for source address 1.
QUESTION 5
Your customer currently has Iwo (2) 5406 modular switches with MSTP configured as their core switches. You are proposing a new solution.
What would you explain regarding the Aruba CX VSX switch pair when the Primary VSX node is replaced and the system MAC is replaced?
A.
VSX will select the MAC address from a node that is the lower ID.
B.
Configure vMAC on the Primary VSX node under VSX to retain MAC after hardware replacement.
C.
VSX will select the MAC address from a node that is a higher ID.
D.
During the initial VSX configuration, the system-mac is assigned with a fixed MAC based on VSX ID.
Correct Answer: D
Explanation
Explanation/Reference:
The system-mac command is used to configure a fixed MAC address for the VSX system. This MAC address is used as the source MAC address for all routed traffic from the VSX node. The system-mac command is highly recommended for preventing traffic disruptions when the primary VSX switch restores after the secondary VSX switch, such as during a primary switch hardware replacement or a power outage 2. During the initial VSX configuration, the system-mac is assigned with a fixed MAC based on VSX ID. The system-mac command can be used to change this default MAC address if needed 2. Therefore, answer D is correct. References: 1: Aruba Campus Access documents and learning resources 2: system-mac - Aruba
QUESTION 6
You are proposing new CX 8360 VSX switches to replace a customer's existing core switches.
The customer is concerned about the possibility of a split-brain scenario between the VSX pair.
How is the VSX pair affected when the ISL is down and keepalive is up?
A.
The VSX pair is out-of-sync.
B.
The VSX pair nodes are still forwarding traffic.
C.
The VSX LAGs are in a degraded state.
D.
The VSX pair is not at risk.
Correct Answer: D
QUESTION 7
A WLAN architect is reviewing roaming standards. The requirement is to let APs and clients exchange radio measurement information that can help clients make better roaming choices.
Which standard addresses this requirement?
A.
802.11k
B.
802.11r
C.
802.11w
D.
802.3at
Correct Answer: A
Explanation
Explanation/Reference:
802.11k is the correct answer because it defines radio resource measurement mechanisms that help clients learn more about the surrounding RF environment, including neighbor-related information. This can improve roaming efficiency by giving the client more useful data when selecting a candidate AP. 802.11r is focused on fast transition keying and reduced reauthentication delay. 802.11w protects management frames, and 802.3at is a PoE standard unrelated to WLAN roaming intelligence.
QUESTION 8
An AOS 10 deployment uses APs that authenticate clients against a cloud-based RADIUS service. The customer wants the RADIUS conversation protected in transit between the APs and the RADIUS server.
Which solution should be used?
A.
Configure EAP-TLS on all clients only
B.
Use RadSec between the APs and the RADIUS server
C.
Enable GRE between APs and gateways
D.
Change the SSID to WPA3-Personal
Correct Answer: B
Explanation
Explanation/Reference:
RadSec is the right answer because it protects RADIUS traffic by carrying it over TLS, providing confidentiality and server authentication for the AAA exchange path. This addresses the stated concern about exposure between the AP and the cloud-based RADIUS service. EAP-TLS strengthens client authentication but does not itself secure the RADIUS transport hop in the same way. GRE is a tunneling technology unrelated to RADIUS protection, and WPA3-Personal changes the client access method rather than securing the AP-to-RADIUS transport.
QUESTION 9
Which network components communicate using the RADIUS protocol for authentication and accounting?
A.
an access point and the endpoint device
B.
a Network Access Server and a RADIUS authentication server
C.
an endpoint device and a RADIUS authentication server
D.
a Network Access Server and an endpoint device
Correct Answer: B
QUESTION 10
In an AOS-10 architecture using an AP, a gateway and traffic forwarding mode * mixed, what happens when a client connects to an open enhanced 5SID where their VLAN assignment will be bridged?
A.
Authenticated Diffie-Hellman is not utilized
B.
RADIUS protocol is utilized.
C.
No encryption is applied.
D.
The gateway will not respond.
Correct Answer: A
QUESTION 11
Your customer has an Aruba CX 6200F VSF stack with two switches. A third member (JL726A) needs to be added to the VSF configuration.
What e the configuration that enables the new devices to join the VSF?
A.
Option A
B.
Option B
C.
Option C
D.
Option D
Correct Answer: C
Explanation
Explanation/Reference:
According to the Aruba Documentation Portal1, the Aruba CX 6200F VSF stack is a feature that allows you to create a virtual switching framework (VSF) with up to eight members that can be managed as a single logical device. The VSF stack provides benefits such as load balancing, failover, redundancy, and security. To add a new device to the VSF stack, you need to configure the device with the VSF command vsf member and specify the type, link, and secondary-member information. The type of the new device can be one of the following: JL726A, JL726B, JL726C, or JL726D. The link is the interface that connects the new device to the existing VSF members. The secondary-member is an optional parameter that specifies which member will act as a backup in case of a failure. 1: https://www.arubanetworks.com/techdocs/AOS-CX/10.06/HTML/5200-7726/index.html 2: https://buy.hpe.com/us/en/networking/switches/fixed-port-l3-managed-ethernet-switches/6000-switch-products/aruba-6200f-48g-4sfp-switch/p/jl726a3: https://addin.co.th/shop/switch/aruba-switch/6200f-series/jl726a/
QUESTION 12
DRAG DROP
List the firewall role derivation flow in the correct order.
Correct Answer:
Explanation
Explanation/Reference:
According to the Aruba Documentation Portal1, the firewall role derivation flow in the correct order is: Server derived role User derived role Authentication default role Initiation role assigned
QUESTION 13
You must ensure the HPEAruba network you are configuring for a client is capable of plug-and-play provisioning of access points.
What enables this capability?
A.
UCC Service
B.
LLDP-MED
C.
SRTP
D.
CSMA
Correct Answer: A
Explanation
Explanation/Reference:
The capability that enables plug-and-play provisioning of access points in an HPE Aruba network is the UCC Service. The UCC Service is a cloud-based service that allows the access points to automatically discover and connect to the Aruba Central management platform without any manual intervention. The UCC Service also provides zero-touch configuration, firmware updates, and monitoring for the access points 1. The other options are incorrect because: B. LLDP-MED: LLDP-MED is a protocol that enhances the interoperability between network devices and IP phones. It does not enable plug-and-play provisioning of access points 2. C. SRTP: SRTP is a protocol that provides encryption and authentication for voice and video traffic. It does not enable plug-and-play provisioning of access points 3. D. CSMA: CSMA is a protocol that regulates how devices share a common medium, such as a wireless channel. It does not enable plug-and-play provisioning of access points.
QUESTION 14
When setting up an AOS-CX VSX pair, which information does the Inter-Switch Link Protocol configuration use in the configuration created?
A.
dead interval is disabled by default
B.
dead interval is based on the value set for hello interval
C.
dead interval is 200ms by default
D.
dead interval is 20s by default
Correct Answer: D
QUESTION 15
In an ArubaOS 10 architecture using an AP and a gateway, what happens when a client attempts to join the network and the WLAN is configured with OWE?
A.
Authentication information is not exchanged
B.
The Gateway will not respond.
C.
No encryption is applied.
D.
RADIUS protocol is utilized.
Correct Answer: A
Explanation
Explanation/Reference:
This is the correct statement about what happens when a client attempts to join the network and the WLAN is configured with OWE (Opportunistic Wireless Encryption). OWE is a standard that provides encryption for open networks without requiring any authentication or credentials from the client or the network. OWE uses a Diffie-Hellman key exchange mechanism to establish a secure session between the client and the AP without exchanging any authentication information. The other options are incorrect because they either describe scenarios that require authentication or encryption methods that are not used by OWE. References: https://www.arubanetworks.com/assets/wp/WP_WiFi6.pdf https://www.arubanetworks.com/assets/ds/ DS_AP510Series.pdf
QUESTION 16
When setting up an Aruba CX VSX pair, which information does the Inter-Switch Link Protocol configuration use in the configuration created?
A.
QSVI
B.
MAC tables
C.
UDLD
D.
RPVST+
Correct Answer: B
Explanation
Explanation/Reference:
The information that the Inter-Switch Link Protocol configuration uses in the configuration created is B. MAC tables. The Inter-Switch Link Protocol (ISL) is a protocol that enables the synchronization of data and state information between two VSX peer switches. The ISL uses a version control mechanism and provides backward compatibility regarding VSX synchronization capabilities. The ISL can span long distances (transceiver dependent) and supports different speeds, such as 10G, 25G, 40G, or 100G1. One of the data components that the ISL synchronizes is the MAC table, which is a database that stores the MAC addresses of the devices connected to the switch and the corresponding ports or VLANs. The ISL ensures that both VSX peers have the same MAC table entries and can forward traffic to the correct destination 2. The ISL also synchronizes other data components, such as ARP table, LACP states for VSX LAGs, and MSTP states 2.
QUESTION 17
Refer to the exhibit.
With Core-1. what is the default value for config-revision?
A.
0
B.
1
C.
1-0
D.
0. 0
Correct Answer: A
Explanation
Explanation/Reference:
The default value for config-revision on Core-1 is 0. Config-revision is a parameter that indicates the configuration version of a VSX pair. It is used to synchronize the configuration between the VSX peers and to detect any configuration mismatch. The config-revision value is set to 0 by default on both VSX peers and is incremented by 1 every time a configuration change is made on either peer. The other options are incorrect because they do not reflect the default value of config-revision. References: https://www.arubanetworks.com/techdocs/AOS-CX/10.04/HTML/5200-6728/bk01- ch07.html (https://www.arubanetworks.com/techdocs/AOS-CX/10.04/HTML/5200-6728/bk01-ch02.html)
QUESTION 18
A customer is looking Tor a wireless authentication solution for all of their loT devices that meet the following requirements
1. The wireless traffic between the IoT devices and the Access Points must be encrypted 2. Unique passphrase per device 3. Use fingerprint information to perform role-based access
Which solutions will address the customer's requirements? (Select two.)
A.
MPSK and an internal RADIUS server
B.
MPSK Local with MAC Authentication
C.
ClearPass Policy Manager
D.
MPSK Local with EAP-TLS
E.
Local User Derivation Rules
Correct Answer: CD
Explanation
Explanation/Reference:
The correct answers are C and D. MPSK (Multi Pre-Shared Key) is a feature that allows multiple PSKs to be used on a single SSID, providing device-specific or group-specific passphrases for enhanced security and deployment flexibility for headless IoT devices 1. MPSK requires MAC authentication against a ClearPass Policy Manager server, which returns the encrypted passphrase for the device in a RADIUS VSA2. ClearPass Policy Manager is a platform that provides role-and device-based network access control for any user across any wired, wireless and VPN infrastructure 3. ClearPass Policy Manager can also use device profiling and posture assessment to assign roles based on device fingerprint information 4. MPSK Local is a variant of MPSK that allows the user to configure up to 24 PSKs per SSID locally on the device, without requiring ClearPass Policy Manager5. MPSK Local can be combined with EAP-TLS (Extensible Authentication Protocol- Transport Layer Security), which is a secure authentication method that uses certificates to encrypt the wireless traffic between the IoT devices and the access points 6. EAP-TLS can also use device certificates to perform role-based access control 6. Therefore, both ClearPass Policy Manager and MPSK Local with EAP-TLS can meet the customer's requirements for wireless authentication, encryption, unique passphrase, and role-based access for their IoT devices. MPSK and an internal RADIUS server is not a valid solution, because MPSK does not support internal RADIUS servers and requires ClearPass Policy Manager789. MPSK Local with MAC Authentication is not a valid solution, because MAC Authentication does not encrypt the wireless traffic or use fingerprint information for role-based access 2. Local User Derivation Rules are not a valid solution, because they do not provide unique passphrase per device or use fingerprint information for role-based access101112.
QUESTION 19
What is used to retrieve data stored in a Management Information Base (MIS)?
A.
SNMPv3
B.
DSCP
C.
TLV
D.
CDP
Correct Answer: A
Explanation
Explanation/Reference:
The correct answer is A. SNMPv3. SNMPv3 is a protocol that is used to retrieve data stored in a Management Information Base (MIB), which is a database of managed objects in a network. SNMPv3 provides security and access control features that are not available in earlier versions of SNMP. SNMPv3 can also use encryption to protect the data from unauthorized access or modification. According to the Aruba Certified Professional ?Campus Access document1, one of the skills that this certification validates is: Implement and Analyze the output from common network monitoring tools The document also mentions that the candidate should have a distinguished understanding of different protocols across vendors, which implies that they should be familiar with SNMPv3 and how it can be used to access MIB data.
QUESTION 20
An administrator is creating a guest SSID that must encrypt user traffic but must not require credentials or 802.1X authentication.
Which wireless security method should the administrator select?
A.
WPA3-Personal
B.
WPA3-Enterprise
C.
OWE
D.
Open with captive portal only
Correct Answer: C
Explanation
Explanation/Reference:
OWE, also called Enhanced Open in many Aruba workflows, is intended for situations where encryption is required but user authentication is not. It protects traffic on an otherwise open network by establishing encryption without using a shared password or 802.1X. WPA3-Personal requires a passphrase, and WPA3-Enterprise requires 802.1X with a RADIUS-based authentication workflow. A purely open network with captive portal does not provide over-the-air encryption before portal interaction.
QUESTION 21
You are configuring Policy Based Routing (PBR) for a subnet that will be used to test a new default route for your network Traffic originating from 10.2.250.0/24 should use a new default route to 10.1.1.253. Other non-default routes for this subnet should not be affected by this change.
What are two parts of the solution for these requirements? (Select two.)
A.
Option A
B.
Option B
C.
Option C
D.
Option D
E.
Option E
Correct Answer: CE
Explanation
Explanation/Reference:
Two parts of the solution for these requirements are Option C and Option E. Option C is a part of the solution because it defines a policy-based routing action list named route_test, which specifies the next hop IP address as 10.1.1.253 for the matching traffic. This is the new default route that the user wants to use for the subnet 10.2.250.0/24. The interface null parameter indicates that the traffic will be routed to the next hop without using a specific interface 1. Option E is a part of the solution because it applies the policy-based routing action list route_test to the VLAN interface 250, which has an IP address of 10.2.250.1/24. This is the subnet that the user wants to test the new default route for. The apply policy command enables policy-based routing on the interface and associates it with the action list 2. Option A is not a part of the solution because it defines a policy-based routing action list named route_test, but does not specify the next hop IP address as 10.1.1.253, which is the new default route that the user wants to use. Instead, it specifies a next hop IP address of 10.1.1.254, which is different from the requirement. Option B is not a part of the solution because it defines a policy-based routing action list named route_test, but does not specify any next hop IP address at all, which is necessary for policy-based routing to work. Instead, it specifies an interface null parameter without any IP address, which is invalid. Option D is not a part of the solution because it applies the policy-based routing action list route_test to the VLAN interface 200, which has an IP address of 10.2.200.1/24. This is not the subnet that the user wants to test the new default route for, but a different subnet that should not be affected by this change.
QUESTION 22
You are setting up a customer's 150 headless loT devices that do not support 802.1 X.
What should you use?
A.
Multiple Pre-Shared Keys (MPSK) Local
B.
Multiple Pre-Shared Keys (MPSK) with WPA3-AES
C.
HPE Aruba Networking ClearPass profiling with MAC-AUTH
D.
HPE Aruba Networking ClearPass profiling with WPA-PSK
Correct Answer: A
QUESTION 23
A customer wants to improve guest user experience because devices that wake from sleep are repeatedly redirected to the captive portal splash page.
What should be enabled?
A.
MAC caching on the splash page workflow
B.
Dynamic authorization on the switch
C.
OSPF graceful restart
D.
Port mirroring on uplinks
Correct Answer: A
Explanation
Explanation/Reference:
MAC caching is the correct feature because it allows returning guest devices to be recognized by their MAC address after the initial successful portal interaction, reducing the need to present the splash page repeatedly. This is a common user-experience improvement for guest access environments where devices often sleep and reconnect. Dynamic authorization is an AAA policy-change mechanism, not a guest portal convenience feature. OSPF graceful restart and port mirroring are unrelated to captive portal behavior.
QUESTION 24
With the CX 6000 48G switch with uplinks of 1/1/47 and 1/1/48, what does the switch do when a client port detects a loop and tx-disable parameter is used?
A.
The ports that confirmed the loop are disabled.
B.
The ports that transmitted and received the loop are disabled.