New Year Sale Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

HP HPE7-A07 Aruba Certified Campus Access Mobility Expert Written Exam Exam Practice Test

Page: 1 / 13
Total 126 questions

Aruba Certified Campus Access Mobility Expert Written Exam Questions and Answers

Question 1

Refer to the exhibit.

Question # 1

To which devices has AP-1 established tunnels?

Options:

A.

A pair of gateways within a cluster

B.

A pair of switches running VXLAN

C.

A single gateway within a cluster

D.

A pair of standalone gateways

Question 2

You are a wireless network administrator at an outdoor container yard. A new multicast application that communicates with the GPS on the container handling equipment is being added to the network.

Which setting will increase the reliability and send traffic at the highest possible data rate?

Options:

A.

Increase the basic rate from 6 to 24 Mbps.

B.

Multicast Transmission Optimization

C.

Dynamic Multicast Optimization

D.

Enable WiFi Multimedia.

Question 3

You recently added ClearPass as an authentication server to an HPE Aruba Networking Central group. RADIUS authentication with Local User Roles (LUR) works fine Out the same access points cannot use Downloadable User Roles (DUR).

What should he corrected in this configuration to fa the issue with DUR?

Options:

A.

Add a new Enforcement Policy of type ‘’WEBAUTH’’ on ClearPass and associate it with the matching service on ClearPass

B.

Add the correct IP addresses or IP subnets of the Network Access Devices (NADs) under the "Devices" tab on ClearPass

C.

Replace the AP's expiree digital certificate using the "crypto pki-import pem serverCert" command.

D.

Add the correct values for "CPPM username" and "CPPM Password" m the authentication server configuration on HPE Aruba Networking Central

Question 4

What directly affects the MCS used by wireless stations? (Select two.)

Options:

A.

SNR

B.

retry rate

C.

channel utilization

D.

number of connected clients

E.

frequency band

Question 5

A BGP routing table contains multiple routes to the same destination prefix.

Referring to the table below which route would be marked with a ">" symbol?

Question # 5

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

E.

Option E

Question 6

A customer has deployed an AOS 10 mobility gateway cluster consisting of three controllers at a single site The WLAN is configured to tunnel wireless device traffic to the AOS 10 mobility cluster The clients are authenticated by ClearPass using WPA3-Enterprise (opmode wpa3-aes-ccm-128). The security team has requested the ability to force a wireless device to reauthenticate using ClearPass.

Which steps are required to ensure ClearPass can consistently initiate a change of authorization against an AOS 10 mobility cluster, including during gateway failover scenarios? (Select two)

Options:

A.

set cluster mode to Auto Site under High Availability - Cluster configuration

B.

modify WLAN - SSID - VLAN - Mode Configuration

C.

enable manual cluster configuration under High Availability - Cluster Configuration

D.

enable Dynamic Authorization CoA under High Availability - Cluster Configuration

E.

modify NAS IPv4 address under Security - Advanced - RADIUS Client

Question 7

Match each Group Based Policy (GBP) role description to its respective role ID.

Question # 7

Options:

Question 8

A customer’s infrastructure is set up to use both primary and secondary gateway clusters on the SSID profile based on best practices What is a valid cause tor having an equal spirt in APs connected to the primary and secondary gateway clusters?

Options:

A.

The secondary gateway cluster is heterogeneous

B.

The secondary gateway cluster is homogeneous

C.

The primary gateway cluster is up. out some APs are unable to reach the primary gateway cluster. These APs would connect to the secondary gateway cluster

D.

The primary gateway cluster is up. out some APs cannot reach the secondary gateway cluster. These APs would connect to the secondary gateway cluster

Question 9

in a WLAN network with a tunneled SSID. you see the following events in HPE Aruba Networking Central:

Question # 9

The customer asks you to investigate log messages What should you tell them?

Options:

A.

This indicates a security issue. The client with a MAC address ending with 37 18;0d Is performing a Denial-of-Service attack on your network. You should track down the client and remove it from the network.

B.

This is normal, expected behavior. No further actions are needed.

C.

This indicates a client WLAN driver issue for the client with a MAC address ending with 37:18

:Od. You should upgrade the client WLAN driver.

D.

There is a roaming issue Enable Fast Roaming 802.11r and OKC to resolve the issue.

Question 10

Exhibit.

Question # 10

You updated your gateway to me most recent firmware However after the firmware was updated, the gateway could no longer connect to HPE Aruba Networking Central. Your corporate ITIL procedures require you to implement your backout plan. You connected a console cable to your gateway and saw the following prompt.

Cpxload#

in what order, do you need to execute the following commands to return to the previous firmware version?

Question # 10

Options:

Question 11

Exhibit.

Question # 11

What is me expected behavior for ARP traffic sent from H1?

Options:

A.

A2 will drop the ARP traffic.

B.

A2 will send the ARP traffic out of ports 1/1/1-1/1/4.

C.

A2 will flood the ARP traffic out of all interfaces.

D.

A2 will send the ARP traffic out of ports 1/1/1 and 1/1/3.

Question 12

Exhibit.

Question # 12

A network administrator attempts to improve multicast traffic flow and performs some packet captures for validation What can the network administrator conclude from the results?

Options:

A.

The data rate increased from 6 Mops to 300 Mops because Broadcast Multicast optimization (BCMCO) was configured.

B.

The capture taken after optimization does not show a packet length because Multicast Transmission Optimization was configured.

C.

The type flew remains consistent because Dynamic Multicast Optimization (DMO) was configured.

D.

The data rate increased from 6 Mbps to 300 Mops because Dynamic Multicast Optimization (DMO) was configured.

Question 13

A customer reports that their HPE Aruba Networking ClearPass Guest captive portal is not functioning. The page loads but they are unable to browse after pressing connect. They have uploaded a valid and publicly trusted *. aruba-training.com certificate.

Refer to the exhibit.

Question # 13

Question # 13

Which would explain this issue?

Options:

A.

aruba-training.com needs to be entered in the Address field for the ClearPass Guest

B.

captiveportal-login.aruba-training.com needs to be entered in the Address field for the ClearPass Guest

C.

HTTPS certificate is not required in ClearPass Guest

D.

HTTPS wildcard certificates are not supported

Question 14

An ACME company employee complained about a recent poor-quality VoIP call while moving around their office environment. HPE Aruba Networking Central reported a fair UCC score for this call while your VoIP engineer reported that their systems reported a MOS of 2.3. The VoIP devices are operating over the 5GHz frequency band.

What are the possible contributing factors? (Select two)

Options:

A.

Recent renovations have changed the floor plan

B.

The Call Admission Control level is set too low

C.

BSS color mode has not been enabled

D.

The client does not support U-NII-2 or U-NII-2-Extended channels

Question 15

You configured a WPA3-SAE with the following MAC Authentication Role Mapping in Cloud Authentication and Policy:

Question # 15

With further default settings assume a new Android phone is connected to the network. Which role will the client be assigned after connecting for the first time?

Options:

A.

byod

B.

client will be rejected network access

C.

lot-local

D.

unmatched-device

Question 16

A customer's infrastructure is set up to use both primary and secondary gateway clusters on the SSID profile based on best practices. What is a valid cause for having an equal split in APs connected to the primary and secondary gateway clusters?

Options:

A.

The secondary gateway cluster is a heterogeneous cluster with four nodes

B.

The primary gateway cluster is a homogeneous cluster with four nodes

C.

The primary and secondary gateway clusters are up, and the cluster preemption is enabled

D.

The primary and secondary gateway clusters are up, but the cluster preemption is not enabled

Question 17

A Windows device attempts to connect to an 802.1X network but it is not receiving the correct role. TEAP has been configured as the only authentication method in ClearPass. The wireless configuration is correct.

Exhibit.

Question # 17

What is me most likely cause?

Options:

A.

The Windows device needs 10 De configured tor TEAP.

B.

ClearPass requires a second authentication method.

C.

802.1X is not compatible with TEAP in windows device

D.

Only machine authentication should be configured on the Windows device

Question 18

After onboarding three new AOS-10 gateways using the full-setup method into the same HPE Aruba Networking Central group, a customer cannot log in to one of the gateways using the HPE Aruba Networking Central remote console due to an incorrect password.

What is causing this issue?

Options:

A.

The admin password created during the full-setup process is not configured to allow the remote console access

B.

The admin password created at the HPE Aruba Networking Central group level has expired

C.

The admin password created using full-setup does not match the global HPE Aruba Networking Central admin password

D.

The admin password created during the full-setup process does not match the HPE Aruba Networking Central group admin password

Question 19

A customer would like to allow their IT Helpdesk to configure IoT devices to connect to a single SSID using a unique PSK that other devices cannot use.

Which solution would you recommend?

Options:

A.

MPSK AES with HPE Aruba Networking ClearPass

B.

MPSK AES with HPE Aruba Networking Central Cloud Authentication

C.

MPSK Local

D.

MPSK AES with MAC Auth

Question 20

A customer is experiencing authentication failures when clients connect to a new EAP-TLS SSID.

Question # 20

Question # 20

Question # 20

Based on the logs and packet capture above, what is the cause of the failure?

Options:

A.

The client cannot validate the RADIUS server's certificate

B.

The MTU in the path between the AP and HPE Aruba Networking ClearPass is too small

C.

HPE Aruba Networking ClearPass cannot validate the user's certificate

D.

The access point doesn't have the correct root CA certificate installed

Question 21

sw-1 is the master on all VRRP instances. To test the configuration, VLAN 100 was shut on sw-1, and then once the failover occurred, it was brought back up.

What is the expected outcome?

Options:

A.

sw-1 will be the master for all three VRRP instances.

B.

sw-1 will only be the master for VRRP 200 and VRRP 300.

C.

sw-2 will only be the master for VRRP 200 and VRRP 300.

D.

sw-2 will be the master for all three VRRP instances.

Question 22

A manufacturing company depends on FTP, email, and RDP services, which are accessed locally. On Monday morning, RDP sessions are not responsive when users on the employee WLAN download their email and large files from the FTP server simultaneously. The network administrator concludes that the mobility gateway's uplinks are congested when that happens.

Which would be the best option the network engineer can propose in the implementation plan to improve RDP responsiveness?

Options:

A.

Update the employee user role with an ACL on position 3 that puts RDP traffic to a high-priority queue and all other traffic to a low-priority queue

B.

Change the employee WLAN from tunneled to bridged so that the bottleneck in the mobility gateways is removed

C.

Set the WMM voice DSCP value on the employee WLAN to 56 and enable the RDP application layer gateway

D.

Update the spanning-tree configuration from enabled to disabled on the gateway's link aggregation to increase the available bandwidth and avoid congestion

Question 23

You recently added HPE Aruba Networking ClearPass as an authentication server to a group in HPE Aruba Networking Central. RADIUS authentication with Local User Roles (LUR) works fine, but the same access points cannot use Downloadable User Roles (DUR).

What should be corrected in this configuration to fix the issue with DUR?

Options:

A.

Add a new Enforcement Policy of type "WEBAUTH" on ClearPass and associate it with the matching service on ClearPass

B.

Add the correct values for "CPPM Username" and "CPPM Password" in the authentication server configuration on HPE Aruba Networking Central

C.

Uncheck the "Dynamic Authorization" checkbox in the authentication server configuration on HPE Aruba Networking Central

D.

Modify the shared secret on the switch to match CPPM using the "radius-server host" command

Question 24

An OSPF router has learned a path to an external network by both an E1 and an E2 advertisement. Both routes have the same path cost. Which path will the router prefer?

Options:

A.

The router will use both paths equally utilizing ECMP.

B.

Both routes will be suppressed until the path conflict has been resolved.

C.

The router will prefer the E1 path.

D.

The router will prefer the E2 path.

Question 25

The ACME company has an AOS-CX 6200 switch stack with an uplink oversubscription ratio of 9.6:1. They are considering adding two more nodes to the stack without adding any additional uplinks due to cabling constraints One of their architects has expressed concerns that their critical UDP traffic from both wired and bridged AP clients will encounter packet drops. They have already applied the following configuration:

Question # 25

Question # 25

Question # 25

Which strategy will complement this solution to achieve their objective?

Options:

A.

edge mark lower priority TCP traffic with AF12

B.

edge mark critical UDP Traffic with CSS

C.

edge mark lower priority TCP traffic with AF11

D.

edge mark critical UDP traffic with AF42

Question 26

Question # 26

A network administrator attempts to improve multicast traffic flow and performs some packet captures for validation. What can the network administrator conclude from the results?

Options:

A.

The data rate increased from 6 Mbps to 300 Mbps because Broadcast Multicast Optimization (BCMCO) was configured.

B.

The type field remains consistent because Dynamic Multicast Optimization (DMO) was configured.

C.

The data rate increased from 6 Mbps to 300 Mbps because Dynamic Multicast Optimization (DMO) was configured.

D.

The capture taken after optimization does not show a packet length because Multicast Transmission Optimization was configured.

Question 27

A customer is running out of IP addresses in a network segment. What will happen If they add an additional IPsubnet to the same VLAN?

Options:

A.

Broadcasts for me two subnets win arrive on all ports in the same VLAN

B.

IGMP will not work in both of the subnets in the same VLAN

C.

This would result in a single SVI using two subinterfaces.

D.

Users can reach each other and establish PTP traffic without passing an L3 point in the same VLAN

Question 28

Which statement is true given the following CLI output from a CX 6300?

Question # 28

Options:

A.

The underlay loopback addresses are in the 172 21 11 x range.

B.

There are two anycast addresses m me overlay fabric.

C.

Duplicate MAC addresses were detected in the overlay fabric

D.

There are three active client overlay VLANs in the overlay fabric

Question 29

A customer is starting to test AAA on their edge switch interfaces. The client device support team is concerned about clients being denied access to the network due to mistakes in configuration or reachability to the authentication servers.

What should be enabled to address the concerns of the client device support team? (Select two)

Options:

A.

Configure onboarding-method concurrent

B.

Configure the critical role

C.

Configure auth-mode multi-device

D.

Configure the fallback role

E.

Configure port-access radius-override

Question 30

A network administrator wants to configure an 802 1X supplicant for a wireless network that includes the following:

1. AES encryption

2. EAP-MSCHAPv2-based user and machine authentication

3. validation of server certificate in Microsoft Windows 10

The network administrator creates a WLAN profile and selects the change connection settings option Then the network administrator changes the security type to Microsoft Protected EAP (PEAP) and enables user and machine authentication under Additional Settings.

What must the network administrator do next to accomplish the task?

Options:

A.

Enable user authentication

B.

Change the security type to Microsoft: Smart Card or other certificate.

C.

Change default RC4 encryption for AES

D.

Enable server certificate validation

Question 31

An existing AOS-10 wireless deployment is expanding its zero-trust wireless network to multiple locations. The requirement is to propagate role information to enforce group-based policies for wireless client traffic across all locations.

To achieve this goal, which must be configured in this infrastructure?

Options:

A.

Configure the gateways to mobility type and configure the Roles under System → Client Roles in HPE Aruba Networking Central

B.

Configure "use switch fabric for role propagation" under Security → Client Roles in HPE Aruba Networking Central

C.

Overlay campus switch fabric with CX switches

D.

Tunneled SSIDs with gateways

Question 32

A customer is evaluating device profiles on a CX 6300 switch. The test device has the following attributes:

• MAC address = 81:cd:93:13:ab:31

• LLDP sys-desc = iotcontroller

The test device is being assigned to the ‘’lot-dev’' role However, the customer requires the "lot-prod’’ role be applied.

Question # 32

Given the configuration, what is causing the "iot-dev" role to be applied to the device'?

Options:

A.

The test device does not support CDP.

B.

The device-profile precedence order is not configured.

C.

An external RADIUS server is unreachable.

D.

The LLDP system description matches the IIdp-group configuration.

Question 33

A customer's infrastructure is set up to use both primary and secondary gateway clusters on the SSID profile based on best practices. Why do they have an equal split of their 260 APs across the primary and secondary gateway clusters?

Options:

A.

The primary gateway cluster is up, but some APs cannot reach the secondary gateway cluster. These APs would connect to the secondary gateway cluster

B.

The secondary gateway cluster is homogeneous

C.

The secondary gateway cluster is heterogeneous

D.

The primary gateway cluster is up, but some APs cannot reach the primary gateway cluster. These APs would connect to the secondary gateway cluster

Question 34

A customer has recently deployed AP-615s at their new office and is wondering on which band the radios will operate with the default configuration after creating a tri-band SSID. What should you tell them?

Options:

A.

The AP will operate on the 2.4GHz and 6GHz bands

B.

The AP will operate on the 2.4GHz and 5GHz bands

C.

The AP will operate on the 5GHz and 6GHz bands

D.

6GHz will not be used unless manually configured

Question 35

You deployed UBT to securely tunnel traffic from user desktop PCs connected behind VOIP phones Ail other non-UBT dents are connected to a different network. After the deployment users reported interruptions lo their phone service

Options:

A.

The VLAN on which UBT clients are placed is not configured on the switch uplink and traffic from the VoIP phones is being dropped

B.

You tailed to correctly configure a user-defined VRF to support the UBT clients behind the VoIP phones, causing traffic to drop.

C.

Broadcast/multicast packets are copied to both the tunnel and locally, causing duplicate packets and network instability

D.

The UBT client broadcast/multicast packets returned to the same switch port and corrupted the phones IMC table

Question 36

Question # 36

Based on the output above, what is required to associate the GBP policy with a user role?

Options:

A.

Configure a user role called GBP-EMPLOYEE instead of EMPLOYEE

B.

Associate the port-access role to the GBP role using the role ID

C.

Update the port-access GBP policies to reference the EMPLOYEE role

D.

Update the entries in the class maps to reference the EMPLOYEE role

Question 37

A customer with a gateway connected to a device on gigabitethernet 0/0/3 configures an Asset ID TLV on the device for inventory management.

Refer to the exhibit.

Question # 37

The customer mentions the Asset ID is not shown. What is causing the issue?

Options:

A.

MTU size is too small.

B.

Unknown TLVs cannot be displayed.

C.

LLDP-MED needs to be enabled.

D.

LLDP TX is not enabled.

Page: 1 / 13
Total 126 questions