New Year Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

An administrator wants to temporarily deny login access who fail 802.1x authentication functions three or more times. Which process will the administrator need to configure?

A.

EAP termination

B.

blacklisting

C.

captive portal

D.

fail through

Refer to the exhibit.

Which controller connection with the Aruba as the cluster leader?

A.

Controller A

B.

Controller B

C.

Controller C

D.

Controller D

An administrator implements the Aruba AitGroup feature to accommodate the Apple Bonjour service. In this implementation, which protocol advertises devices such as printers, computers, and their services?

A.

LLDP

B.

Multicast DHCP

C.

Multicast DNS

D.

Broadcast DNS

Refer to the exhibit.

The administrator expects the AP to connect to a cluster, but the AP fails to connect. The administrator examines the configuration of an AP from apboot mode shown in the exhibit. What can the administrator determine about the configuration of the AP?

A.

The AP is configured to terminate on a non-cluster Mobility Controller.

B.

The AP is configured as a RAP to terminate on a stand-alone controller.

C.

The AP is configured as a RAP to terminate on a Mobility Master.

D.

The AP is configured to terminate on a Mobility Controller in a cluster.

Refer to the exhibit.

An administrator configures a policy for an AP Group. Port 3 of a RAP is a trunk that connects to a switch at a branch office. VLAN 1 is untagged and VLANs 10 (for data) and 11 (for voice) are tagged. The administrator applies an ACL inbound on Port 3 of the RAP.

How does this configuration affect traffic on Port 3?

A.

It filters traffic from VLAN 10 and 11, but allows traffic from VLAN1.

B.

It filters traffic form VLAN 1, but allows traffic from VLANs 10 and 11.

C.

It allows all traffic form VLANs 1, 10, and 11.

D.

It filters traffic from VLANs 1, 10, and 11.

An administrator implements machine authentication in an 802.1X profile. Which user role will be assigned to the user’s session if machine authentication fails, but the 802.1X user authentication passes for a user who connects?

A.

802.1X default user role

B.

Machine authentication initial user role

C.

802.1X initial user role

D.

Machine authentication default user role

Which forwarding mode is used for a WLAN if a RAP needs to decrypt all user traffic and forward it locally?

A.

Split-tunnel

B.

Bridge

C.

Tunnel

D.

Decrypt-tunnel

Refer to the exhibit.

An administrator implements an L2 cluster of Aruba Mobility Controllers (MCs) as shown in the exhibit. An external RADIUS AAA server authentication clients associated with the Active User Anchor Controller (A-UAC), where the NAS IP address sent from Controller B is 10.254.1.2.

By default, what happens to the user's session when it is handed over to the Standby UAC (S-UAC) after a failover?

A.

The user's session remains active and RADIUS messages can still be processed between the S-UAC and AAA server.

B.

The user's session remains active, but the AAA server cannot implement RADIUS Change of Authorization (CoA).

C.

The user's session is disconnected and has to reconnect, but the S-UAC automatically updates the NAS-IP address on the AAA server to record the event.

D.

The user's session is disconnected and has to reconnect, and no record of this process is stored on the AAA server.

Refer to the exhibit. What can the determined from the command shown in the exhibit?

A.

All the controllers run in standalone mode.

B.

MM2 is the Mobility Master.

C.

VRRP is used for Mobility Master redundancy.

D.

All the controllers run in a cluster.

An administrator needs to authenticate users connected to an ArubaOS-Switch where the switch authenticates the user, assign the firewall policies to the user, and processes some of the users’ traffic. Which connection method should the administrator configure on the ArubaOS-Switch?

A.

Per-user tunneled node

B.

Per-port tunneled node

C.

VLAN tunneled mode

D.

Split-tunneled mode