Labour Day Special Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

HP HPE6-A81 Aruba Certified ClearPass Expert Written Exam Exam Practice Test

Page: 1 / 6
Total 60 questions

Aruba Certified ClearPass Expert Written Exam Questions and Answers

Question 1

What is the Secure SSIO (otherwise referred to as Single SSID) OnBoard deployment service workflow?

Options:

A.

Onboard Provisioning RADIUS service, Onboard Authorization Application service, Onboard Pre-Auth Application service. Onboard Provisioning RADIUS service Onboard B. Provisioning RADIUS service,

B.

Onboard Authorization RADIUS service. Onboard Pre-Auth Application service. Onboard Provisioning RADIUS service Onboard C. C. Provisioning RADIUS service. Onboard Prt-Auth Application service.

C.

Onboard Authorization Application service. Onboard Provisioning RADIUS service Onboard

D.

Provisioning RADIUS service. Onboard Pre-Auth RADIUS service. Onboard Authorization Application service. Onboard Provisioning RADIUS service.

Question 2

Refer to the exhibit.

Question # 2

You have configured an Onboard portal for single SSID provision. During testing you notice that the QuickConnect Application did not display the "Connect" button, only the finish button. To get connected the test user had to manually connect to the secure-HS-5007 SSID but was prompted for a username and password. Using the screenshots as a reference, how would you fix this issue?

Options:

A.

Check the network settings for the correct SSID name spelling.

B.

Install a public signed HTTPS web server certificate on the ClearPass server

C.

Change the network settings to use EAP-TLS for the authentication protocol.

D.

Configure the SSID to support both EAP-PEAP and EAP-TLS authentication method

Question 3

While configuring the service rule conditions which NAS-Port-Type value should be used to differentiate the service for wired and wireless authentication?

Options:

A.

Ethernet (5) and Wireless-802 11 (9)

B.

Ethernet (15) and Wireless-802 II (19)

C.

Ethernet (O)and W.reless-802 11 (1)

D.

Ethernet (19) and Wireless-802 11(18)

Question 4

What is used to validate the EAP Certificate? (Select two.)

Options:

A.

Key usage

B.

Date

C.

Server Identity

D.

SAN entries

E.

Common Name

Question 5

Under OnBoard Management and Control, which option will deny the user from re-enrolling one of his devices with Onboard?

View by Certificate >> Click on the device >> Delete certificate

Options:

A.

Delete this client certificate View by Dev >> Click on the device

B.

Manage Access >> Deny access to this device View by Certificate

C.

Click on the device >> Revoke certificate >> Revoke this client certificate

D.

View by Username >> Click on the user >> Delete Actions >> Delete all devices

Question 6

Which statement is true about Radius IETF attributes Called-Stat ion-Id and Calling-Station-ld?

Options:

A.

Called-Station-ld contains the mac address of the supplicant while Calling-Station-ld contains the mac address of the authenticator.

B.

Called-Station-Id contains the mac address of the supplicant and SSID name while Calling-Station-Id contains the mac address of the authenticator.

C.

Called-Station-ld contains the mac address of the authenticator while Calling-Station-Id contains the mac address of the supplicant.

D.

Called-Station-ld contains the mac address of the authenticator while Calling-Station-ld contains the mac address of the supplicant and SSID name.

Question 7

Which statements art true about Aruba down loadable user roles? (select three)

Options:

A.

Administering downloadable user roles can be difficult for a large enterprise.

B.

Can be applied only on ports or WLAN users authenticated by ClearPass.

C.

Can use these result for other authentication methods not involving ClearPass.

D.

Aruba downloadable user role are universally available across the environment.

E.

Aruba downloadable user role is a built in enforcement template in ClearPass.

F.

Downloadable role names must be defined in Aruba switch or controller.

Question 8

A customer has a Clear Pass cluster deployment with four servers, two servers at the data center and two servers at a large remote site connected over an SO-WAN solution. The customer would like to implement OnGuard. Guest Self-Registration, and 802.1 X authentication across their entire environment. During testing the customer is complaining that users connecting to an Instant Cluster Employee S5ID at the remote site, with the OnGuard Persistent Agent installed are randomly getting their health check missed.

What could be a possible cause of this behavior?

Options:

A.

The traffic on the TCP port 6658 is congested due to the fact that this port is also used by the IPSec keep-alive packets of the SO-WAN solution.

B.

The OnGuard Clients are automatically mapped to the Policy Manager Zone based on their IP range but an ACL on the switch could be blocking access.

C.

The Aruba-user-role received by the IAP is filtering the TCP port 6658 to the Clear Pass servers and after 10 seconds the SSL fallback gets activated and randomly generates the issue

D.

The ClearPass Policy Manager zones have been defined but the local IP subnets have not but properly mapped to the zones and the OnGuard Agent might connect to any of the servers in the cluster.

Question 9

Refer to the exhibit.

Question # 9

A customer it troubleshooting a client not getting the SHV posture updated and the OnGuard agent shows the Health Status Not Known. What could the user do to update the health status?

Options:

A.

connect using an interface that is configured as Managed Interface

B.

reinstall the OnGuard agent from the Wired interface

C.

change the Policy Manager Zone mapping and add the WIRED interface range

D.

modify the agent.conf file and add the WIRED interface to it

Page: 1 / 6
Total 60 questions