An OSPF router has learned a pain 10 an external network by Doth an E1 and an E2 advertisement Both routes have the same path cost Which path will the router prefer?
-
A
The router will prefer the E1 path.
-
B
The router will use Doth paths equally utilizing ECMP.
-
C
The router will prefer the E2 path.
-
D
Both routes will be suppressed until the path conflict has been resolved.
Reveal answer details
Close answer details
Correct answerA
ExplanationIn OSPF, when a router learns about an external network through both E1 and E2 advertisements, and if both have the same path cost, the router will prefer the E1 path. This is because E1 routes consider both the external cost to reach the external network and the internal cost to reach the ASBR, providing a more comprehensive metric. E2 routes only consider the external cost and ignore the internal cost to the ASBR, which could potentially lead to suboptimal routing. Therefore, the router will choose the E1 path due to its more accurate representation of the total path cost.
An AOS 10 multi-site deployment has sites with AP-only bridged SSlDs and other sites with APs and gateways operating tunneled SSiDs. Client session state sync errors exist between secure lab environments and public -facing areas at several sites. What is causing the issues?
-
A
The DTLS connections are down between APs in the lab and APs in public areas
-
B
The affected clients are associated with an SSID with 11r and 11k disabled.
-
C
The sites with issues are the overlay AP with gateway sites because the connection to HPE Aruba Networking central is interrupted
-
D
The sites with issues are the AP-only deployments because the connection to HPE Aruba Networking Central is interrupted
Reveal answer details
Close answer details
Correct answerC
ExplanationIn a multi-site deployment with a mix of bridged and tunneled SSIDs, if there are session sync errors between different areas, it could be due to connectivity issues with the central management platform, which in the case of Aruba, is likely HPE Aruba Networking Central. This interruption could cause inconsistencies in session states across the network.
Exhibit.  Which statement is true?
-
A
The SSID supports RC4 encryption.
-
B
The SSID supports 802.11nac clients.
-
C
The SSID supports implicit beamforming.
-
D
The SSID supports sending neighbor reports.
Reveal answer details
Close answer details
Correct answerB
ExplanationThe SSID supports 802.11ac clients, which is indicated by the "High Throughput" and "Very High Throughput" options being enabled. These are terms associated with the 802.11ac wireless standard, indicating that the SSID can serve clients that support this technology.
Which command would allow you to verity receipt of a CoA message on an AOS 10 GW?
-
A
packet-capture datapath udp 3799
-
B
packet-capture controipath udp 3799
-
C
packet-capture interprocess udp 3799
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationThe Change of Authorization (CoA) messages are used in network access control scenarios and are typically received by the network access server, in this case, an Aruba AOS 10 Gateway. The correct command to verify the receipt of a CoA message is related to the control path traffic because CoA is a control plane function. Option B, packet-capture controlpath udp 3799 , is the correct answer because it specifies capturing control plane traffic on UDP port 3799, which is the standard port for CoA messages. Options A, C, and D are incorrect because: Option A captures data plane traffic, not control plane traffic. Option C's packet-capture interprocess udp 3799 does not refer to a standard command for capturing CoA messages. Option D, tcpdump host-port 3799 , does not specify the correct syntax for capturing traffic on Aruba devices.
A customer has deployed anAOS 10 mobilitygateway cluster consisting of three controllers at a single site The WLAN is configured to tunnel wireless device traffic to the AOS 10 mobilitycluster.The clients areauthorized to use WPA2-Personal.An end-userhas opened a ticket with the helpdesk stating they cannot connect their client device to the network.There are other devices currently associated with the SSID with no issues.  Reviewing the output, what Is the issue?
-
A
The RADIUS response from the authentication server is
-
B
The client device has an invalid certificate
-
C
The client device has an invalid pre-shared key.
-
D
transition mode is not enabled
Reveal answer details
Close answer details
Correct answerC
ExplanationThe issue indicated by the output is an invalid pre-shared key (PSK). The logs show multiple failures during the WPA2 key exchange process, which points to a mismatch between the PSK configured on the client device and the PSK expected by the AOS 10 mobility gateway.
Question 6
Multiple choice
Anetworkadministrator accesses HPE Aruba Networking Central and notices that visitors consume too much internet bandwidth starving employee traffic when accessing an external service.Therefore,the administrator wants to limitwireless bandwidth to 60 Mops in both directions among all users in the voice rote and no more than 10 Mops in both directions for YouTube traffic. Deep packet inspection, web contentclassification, andfirewall visibility are enabled. Which configurations are required to accomplish this task? (Select two.) 
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answersB, D
ExplanationTo achieve the bandwidth limits set by the network administrator, both per-application and total limits need to be configured. Option B shows the configuration for setting a per-application bandwidth limit, which can restrict YouTube traffic to 10 Mbps in both directions. Option D shows the configuration for setting a total bandwidth limit for all users within the voice role to 50000 Kbps (or 50 Mbps), satisfying the requirement to restrict total wireless bandwidth. By applying these configurations in HPE Aruba Networking Central, the administrator will successfully implement the necessary controls to ensure that visitor traffic does not impede the network performance for employee traffic, aligning with the capabilities of Aruba solutions to manage and prioritize network resources effectively.
A customer's infrastructure is set up to use Doth primary and secondary gateway clusters on the SSID profile What is a valid reason for the AP to failover to the secondary gateway cluster?
-
A
The primary gateway cluster is up. out the AP is unable to reach the primary gateway cluster.
-
B
The secondary gateway cluster is up. hut the AP is unable to reach the secondary gateway cluster
-
C
The secondary gateway cluster is heterogeneous.
-
D
The secondary gateway cluster is homogeneous.
Reveal answer details
Close answer details
Correct answerA
ExplanationIn Aruba's infrastructure, the Access Points (APs) are configured with primary and secondary gateway clusters to ensure connectivity and resiliency. The APs will failover to the secondary gateway cluster if they are unable to reach the primary gateway cluster, even if the primary cluster is operational. This mechanism ensures that the APs maintain connectivity to the network infrastructure for continuous service delivery.
A network technician racked up two 9240 mobility gateways in a single cluster that will be terminating 1700 APs in a medium-sized branch office Next, the technician cabled the gateways with two SFP28 Direct Attach Copper (DAC) cables, distributed between a two-member core switching stack and powered them up. What must the network administrator do next regarding the gateway configuration to ensure maximum wired bandwidth utilization?
-
A
Map two physical ports to a port channel on each gateway.
-
B
Make an ports trunk interfaces and permit data VLANs
-
C
Disable the spanning tree and allocate unique VLANs to each port.
-
D
Manually set 25Gbps speeds on all ports.
Reveal answer details
Close answer details
Correct answerA
ExplanationTo maximize wired bandwidth utilization, especially when multiple APs are terminating on mobility gateways, it's best practice to aggregate physical ports into a port channel. This provides redundancy and increased bandwidth by combining the throughput of multiple ports.
You configured a tunneled SSID with captive portal and a ClearPass Guest Self Registration workflow when testing and launching the self-registration workflow, after successful registration, the login action shows the following error:  What is the best solution to resolve this error?
-
A
You need to include the root and intermediate certificates in the captive portal certificate for your access points
-
B
You need to De connected to the guest SSiD while testing.
-
C
You need to change the Login Address in ClearPass to securelogin arubanetworKs.com
-
D
You need to include the root and intermediate certificates in the captive portal certificate for your gateway
Reveal answer details
Close answer details
Correct answerD
ExplanationIncluding the root and intermediate certificates in the captive portal certificate for the gateway will resolve the error seen during the login action after successful registration. This is necessary to ensure the SSL/ TLS handshake can be completed successfully, as the client browser needs to validate the entire certificate chain.
Question 10
Single choice
A customer would like to allow their IT Helpdesk to configure loT devices to connect lo a single SSID using a unique PSK that other devices cannot use. Which solution would you recommend?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationMulti-Pre-Shared Key (MPSK) with ClearPass is the recommended solution for a scenario where the IT Helpdesk needs to configure IoT devices to connect to a single SSID using unique PSKs. MPSK allows for the use of different PSKs on the same SSID, and ClearPass enables the management of these unique keys efficiently.
Question 11
Multiple choice
The ACME company has an AOS-CX 6200 VSF switch slack with an uplink over subscription ratio of 9.6:1. They have indicated that their low-priority TCP traffic has been flagged with a DSCP marking coloring them yellow. Refer to the exhibit.   They are considering adding two more nodes to thestack without adding any additional uplinks due to existing wiring constraints.One of their architects has suggested adding the following configuration:  What would be the impact of applying the acmethreshold profile as shown? (Select two.)
-
A
All upper-layer protocol traffic egressing LAG1 will be subject to drop probability.
-
B
All TCP traffic egressing LAG1 wail be subject to drop probability
-
C
Only VoIP packets egressing queue 5 on LAG1 will likely be protected from uplink over-utilization.
-
D
VoIP packets egressing any queue on LAG1 will more likely be protected from uplink over-utilization
-
E
Yellow-flagged TCP traffic egressing LAG1 will be subject to drop probability
Reveal answer details
Close answer details
Correct answersA, E
ExplanationApplying the 'acmethreshold' profile as shown in the exhibit would set a minimum and maximum threshold for queue 0, which affects the drop probability for traffic that exceeds these thresholds. The yellow marking indicates a medium drop precedence, so yellow-flagged traffic would be more likely to be dropped when congestion occurs, and the uplink is over-utilized. This action is intended to protect higher-priority traffic, such as VoIP, by giving it a lower probability of being dropped.
|