ExamDumpster

Free HPE6-A84 sample questions

Real questions from the Aruba Network Security Expert practice bank, with the correct answer and an explanation for each one. No junk, no filler.

Try them in the simulator Same questions, with study, timed and flashcard modes.

Showing 8 of 17 free sample questions.

Question 1Choose one

You are designing an Aruba ClearPass Policy Manager (CPPM) solution for a customer. You learn that the customer has a Palo Alto firewall that filters traffic between clients in the campus and the data center.Which integration can you suggest? A.Sending Syslogs from the firewall to CPPM to signal CPPM to change the authentication status for misbehaving clientsB.Importing clients’ MAC addresses to configure known clients for MAC authentication more quicklyC.Establishing a double layer of authentication at both the campus edge and the data center DMZD.Importing the firewall's rules to program downloadable user roles for AOS-CX switches more quickly

Question 2Choose one

Refer to the scenario.A customer has an Aruba ClearPass cluster. The customer has AOS-CX switches that implement 802.1X authentication to ClearPass Policy Manager (CPPM).Switches are using local port-access policies.The customer wants to start tunneling wired clients that pass user authentication only to an Aruba gateway cluster. The gateway cluster should assign these clients to the “eth-internet" role. The gateway should also handle assigning clients to their VLAN, which is VLAN 20.The plan for the enforcement policy and profiles is shown below:The gateway cluster has two gateways with these IP addresses:• Gateway 1o VLAN 4085 (system IP) = 10.20.4.21o VLAN 20 (users) = 10.20.20.1o VLAN 4094 (WAN) = 198.51.100.14• Gateway 2o VLAN 4085 (system IP) = 10.20.4.22o VLAN 20 (users) = 10.20.20.2o VLAN 4094 (WAN) = 198.51.100.12• VRRP on VLAN 20 = 10.20.20.254The customer requires high availability for the tunnels between the switches and the gateway cluster. If one gateway falls, the other gateway should take over its tunnels. Also, the switch should be able to discover the gateway cluster regardless of whether one of the gateways is in the cluster.You are setting up the UBT zone on an AOS-CX switch.Which IP addresses should you define in the zone? A.Primary controller = 10.20.4.21; backup controller = 10.20.4.22B.Primary controller = 198.51.100.14; backup controller = 10.20.4.21C.Primary controller = 10.20.4.21; backup controller, not definedD.Primary controller = 10.20.20.254; backup controller, not defined

Question 3Choose one

Refer to the scenario.A customer requires these rights for clients in the “medical-mobile” AOS firewall role on Aruba Mobility Controllers (MCs):Permitted to receive IP addresses with DHCPPermitted access to DNS services from 10.8.9.7 and no other serverPermitted access to all subnets in the 10.1.0.0/16 range except denied access to 10.1.12.0/22Denied access to other 10.0.0.0/8 subnetsPermitted access to the InternetDenied access to the WLAN for a period of time if they send any SSH trafficDenied access to the WLAN for a period of time if they send any Telnet trafficDenied access to all high-risk websitesExternal devices should not be permitted to initiate sessions with “medical-mobile” clients, only send return traffic.The exhibits below show the configuration for the role.There are multiple issues with this configuration. What is one change you must make to meet the scenario requirements? (In the options, rules in a policy are referenced from top to bottom. For example, “medical-mobile” rule 1 is “ipv4 any any svc-dhcp permit,” and rule 8 is “ipv4 any any any permit”.) A.In the “medical-mobile” policy, move rules 2 and 3 between rules 7 and 8.B.In the “medical-mobile” policy, change the subnet mask in rule 3 to 255.255.248.0.C.Move the rule in the “apprf-medical-mobile-sacl” policy between rules 7 and 8 in the “medical-mobile” policy.D.In the “medical-mobile” policy, change the source in rule 8 to “user.”

Question 4Choose one

A company has an Aruba ClearPass server at 10.47.47.8, FQDN radius.acnsxtest.local. This exhibit shows ClearPass Policy Manager's (CPPM's) settings for an Aruba Mobility Controller (MC).The MC is already configured with RADIUS authentication settings for CPPM, and RADIUS requests between the MC and CPPM are working. A network admin enters and commits this command to enable dynamic authorization on the MC: aaa rfc-3576-server 10.47.47.8But when CPPM sends CoA requests to the MC, they are not working. This exhibit shows the RFC 3576 server statistics on the MC:How could you fix this issue? A.Change the UDP port in the MCs’ RFC 3576 server config to 3799.B.Enable RadSec on the MCs’ RFC 3676 server config.C.Configure the MC to obtain the time from a valid NTP server.D.Make sure that CPPM is using an ArubaOS Wireless RADIUS CoA enforcement profile.

Question 5Choose one

A large enterprise is deploying User-Based Tunneling (UBT) using AOS-CX switches at the edge and a cluster of Aruba Gateways at the core. The security architect mandates that all guest traffic must be tunneled to the DMZ gateways, while corporate traffic is tunneled to the Data Center gateways. Both traffic types originate from the same physical switch ports. Which architectural component allows the AOS-CX switch to direct traffic to different gateway clusters based on the user role derived from ClearPass?

Question 6Choose one

You are troubleshooting a Downloadable User Role (DUR) failure on an AOS-CX switch. The switch successfully authenticates the user via ClearPass, but the role fails to download, placing the port in a generic reject state. You verify that the switch has the correct ClearPass root CA certificate installed. A packet capture reveals the switch is attempting to contact ClearPass on port 443 but receiving a reset. Which configuration on the ClearPass Policy Manager is most likely missing?

Question 7Choose one

An organization requires a highly secure authentication flow for their finance department. The requirements are: 1. Users must authenticate using EAP-TLS with a machine certificate. 2. The machine must pass a health check (OnGuard) before full access is granted. 3. If the health check is pending, the user sits in a quarantine role. Which combination of ClearPass Service configurations best achieves this workflow using a single service where possible?

Question 8Choose one

A network administrator needs to implement a 'Headless Device' onboarding process for printers and IoT devices that do not support 802.1X. The goal is to profile them accurately and allow them onto the network only if they match specific device fingerprints. Which set of ClearPass features should be combined to achieve this most securely?

9 more free samples are waiting

Create a free account to unlock the whole HPE6-A84 sample bank, or get full access to all 158 practice questions in the simulator.

Create account