Summer Sale- Special Discount Limited Time 65% Offer - Ends in 0d 00h 00m 00s - Coupon code: netdisc

HP HPE6-A68 Aruba Certified ClearPass Professional (ACCP) V6.7 Exam Practice Test

Page: 1 / 12
Total 116 questions

Aruba Certified ClearPass Professional (ACCP) V6.7 Questions and Answers

Question 1

Which is a valid policy simul-ation types in ClearPass? (Choose three.)

Options:

A.

Enforcement Policy

B.

Posture token derivation

C.

Role Mapping

D.

Endpoint Profiler

E.

Chained simulation

Question 2

Which licenses are included in the built-in Starter kit for ClearPass?

Options:

A.

10 ClearPass Guest licenses, 10 ClearPass Onguard licenses and 10 ClearPass Onboard licenses

B.

25 ClearPass Profiler licenses

C.

25 ClearPass Enterprise licenses

D.

10 ClearPass Enterprise licenses

E.

25 ClearPass Redundancy licenses

Question 3

Which settings need to be validated for a successful EAP-TLS authentication? (Select two.)

Options:

A.

Username and Password

B.

Pre-shared key

C.

WPA2-PSK

D.

Server Certificate

E.

Client Certificate

Question 4

Refer to the exhibit.

Question # 4

Under which circumstances will ClearPass select the Policy Service named ‘Test device group’?

Options:

A.

when the NAD belongs to an Airware device group HQ

B.

when the ClearPass IP address is part of the device group HQ

C.

when the Aruba access point that the client is associated to is part of the device group HQ

D.

when an end user IP address is part of the device group HQ

E.

when the IP address of the NAD is part of the device group HQ

Question 5

Refer to the exhibit.

Question # 5

What can be concluded from the Access Tracker output shown?

Options:

A.

The client used incorrect credentials to authenticate to the network.

B.

ClearPass does not have a service enabled for MAC authentication.

C.

The client MAC address is not present in the Endpoints table in the CrearPass database.

D.

The RADIUS client on the Windows server failed to categorize the service correctly.

E.

The client wireless profile is incorrectly setup.

Question 6

An employee authenticates using a corporate laptop and runs the persistent Onguard agent to send a health check back the Policy Manager. Based on the health of the device, a VLAN is assigned to the corporate laptop.

Which licenses are consumed in this scenario?

Options:

A.

1 Policy Manager license, 1 Onboard License

B.

2 Policy Manager licenses, 1 Onguard License

C.

1 Policy Manager license, 1 Profile License

D.

2 Policy Manager licenses, 2 Onguard licenses

E.

1 Policy Manager license, 1 Onguard License

Question 7

Refer to the exhibit.

Question # 7

Based on the Enforcement Policy configuration shown, when a user with Role Remote Worker connects to the network and the posture token assigned is quarantine, which Enforcement Profile will be applied?

Options:

A.

RestrictedACL

B.

Remote Employee ACL

C.

[Deny Access Profile]

D.

EMPLOYEE_VLAN

E.

HR VLAN

Question 8

Refer to the exhibit.

Question # 8

Based on the configuration of the Enforcement Profiles in the Onboard Authorization service shown, which Onboarding action will occur?

Options:

A.

The device will be disconnected from the network after Onboarding so that an EAP-TLS authentication is not performed.

B.

The device will be disconnected from and reconnected to the network after Onboarding is completed.

C.

The device’s onboard authorization request will be denied.

D.

The device will be disconnected after post-Onboarding EAP-TLS authentication, so a second EAP-TLS authentication is performed.

E.

After logging in on the Onboard web login page, the device will be disconnected form and reconnected to the network before Onboard begins.

Question 9

When is the RADIUS server certificate used? (Select two.)

Options:

A.

During dual SSID onboarding, when the client connects to the Guest network

B.

During EAP-PEAP authentication in single SSID onboarding

C.

During post-Onboard EAP-TLS authentication, when the client verifies the server certificate

D.

During Onboard Web Login Pre-Auth, when the client loads the Onboarding web page

E.

During post-Onboard EAP-TLS authentication, when the server verifies the client certificate

Question 10

An organization implements dual SSID Onboarding. The administrator used the Onboard service template to create services for dual SSID Onboarding.

Which statement accurately describes the outcome?

Options:

A.

The Onboard Provisioning service is triggered when the user connects to the provisioning SSID to Onboard their device.

B.

The Onboard Authorization service is triggered when the user connects to the secure SSID.

C.

The Onboard Authorization service is triggered during the Onboarding process.

D.

The device connects to the secure SSID for provisioning.

E.

The Onboard Authorization service is never triggered.

Question 11

Refer to the exhibit.

Question # 11

An Enforcement Profile has been created in the Policy Manager as shown.

Which action will ClearPass take based on this Enforcement Profile?

Options:

A.

ClearPass will count down 600 seconds and send a RADIUS CoA message to the user to end the user’s session after this time is up.

B.

ClearPass will send the Session-Timeout attribute in the RADIUS Access-Accept packet to the NAD and the NAD will end the user’s session after 600 seconds.

C.

ClearPass will count down 600 seconds and send a RADIUS CoA message to the NAD to end the user’s session after this time is up.

D.

ClearPass will send the Session-Timeout attribute in the RADIUS Access-Request packet to the NAD and the NAD will end the user’s session after 600 seconds.

E.

ClearPass will send the Session-Timeout attribute in the RADIUS Access-Accept packet to the User and the user’s session will be terminated after 600 seconds.

Question 12

What is the purpose of RADIUS CoA (RFC 3576)?

Options:

A.

to force the client to re-authenticate upon roaming to a new Controller

B.

to apply firewall policies based on authentication credentials

C.

to validate a host MAC address against a whitelist or a blacklist

D.

to authenticate users or devices before granting them access to a network

E.

to transmit messages to the NAD/NAS to modify a user’s session status

Question 13

What is the certificate format PKCS #7, or .p7b, used for?

Options:

A.

Certificate Signing Request

B.

Binary encoded X.509 certificate

C.

Binary encoded X.509 certificate with public key

D.

Certificate with an encrypted private key

E.

Certificate chain

Question 14

If the “Alerts” tab in an access tracker entry shows the following error message: “Access denied by policy”, what could be a possible cause for authentication failure?

Options:

A.

Configuration of the Enforcement Policy.

B.

An error in the role mapping policy.

C.

Failure to select an appropriate authentication method for the authentication request.

D.

Implementation of a firewall policy on ClearPass.

E.

Failure to find an appropriate service to process the authentication request.

Question 15

Refer to the exhibit.

Question # 15

Based on the configuration for ‘maximum devices’ shown, which statement accurately describes its settings?

Options:

A.

The user cannot Onboard any devices.

B.

It limits the total number of devices that can be provisioned by ClearPass.

C.

It limits the total number of Onboarded devices connected to the network.

D.

It limits the number of devices that a single user can Onboard.

E.

It limits the number of devices that a single user can connect to the network.

Question 16

Which statement is true? (Choose two.)

Options:

A.

Mobile device Management is the result of Onboarding.

B.

Third party Mobile Device Management solutions can be integrated with ClearPass.

C.

Mobile Device Management is the authentication that happens before Onboarding.

D.

Mobile Device Management is an application container that is used to provision work applications.

E.

Mobile Device Management is used to control device functions post-Onboarding.

Question 17

Which CLI command is used to upgrade the image of a ClearPass server?

Options:

A.

Image update

B.

System upgrade

C.

Upgrade image

D.

Reboot

E.

Upgrade software

Page: 1 / 12
Total 116 questions