New Year Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

In AOS 10. which session-based ACL below will only allow ping from any wired station to wireless clients but will not allow ping from wireless clients to wired stations"? The wired host ingress traffic arrives on a trusted port.

A.

ip access-list session pingFromWired any user any permit

B.

ip access-list session pingFromWired user any svc-icmp deny any any svc-icmp permit

C.

ip access-list session pingFromWired any any svc-icmp permit user any svc-icmp deny

D.

ip access-list session pingFromWired any any svc-icmp deny any user svc-icmp permit

A customer is looking Tor a wireless authentication solution for all of their loT devices that meet the following requirements

- The wireless traffic between the IoT devices and the Access Points must be encrypted

- Unique passphrase per device

- Use fingerprint information to perform role-based access

Which solutions will address the customer's requirements? (Select two.)

A.

MPSK and an internal RADIUS server

B.

MPSK Local with MAC Authentication

C.

ClearPass Policy Manager

D.

MPSK Local with EAP-TLS

E.

Local User Derivation Rules

With the Aruba CX switch configuration, what is the Active Gateway feature that is used for and is unique to VSX configuration?

A.

VRRP and Active gateway are mutually exclusive on a VLAN

B.

VRID is set automatically as SVI vlan id

C.

VRIDs need to be non-overlapping with VRRP

D.

VRRP and Active Gateway can be configured on a single VLAN for interoperability

Using Aruba best practices what should be enabled for visitor networks where encryption is needed but authentication is not required?

A.

Wi-Fi Protected Access 3 Enterprise

B.

Opportunistic Wireless Encryption

C.

Wired Equivalent Privacy

D.

Open Network Access

Refer to Exhibit:

With Access-1, What needs to be identically configured With MSTP to load-balance VLANS?

A.

Spanning-tree bpdu-guard setting

B.

Spanning-tree instance vlan mapppjng

C.

spanning-tree Cist mapping

D.

Spanning-tree root-guard setting

Your manufacturing client is having installers deploy seventy headless scanners and fifty IP cameras in their warehouse These new devices do not support 802 1X authentication.

How can HPE Aruba reduce the IT administration overhead associated with this deployment while maintaining a secure environment using MPSK?

A.

Have the installers generate keys with ClearPass Self Service Registration.

B.

Have the MPSK gateway derive the unique pre-shared keys based on the MAC OUI.

C.

Use MPSK Local to automatically provide unique pre-shared keys for devices.

D.

MPSK Local will allow the cameras to share a key and the scanners to share a different key

Match the topics with the underlying technologies (Options may be used more than once or not at all.)

Your customer has four (4) Aruba 7200 Series Gateways and two (2) 7000 Series Gateways. The customer wants to form a cluster with these Gateways. What design consideration would prevent you from using all of those Gateways?

A.

Multiple versions between Gateways in the same cluster profile are not allowed AOS 10.x.

B.

A heterogeneous cluster is not supported in AOS 10.x.

C.

The AP load should be lowest value of worst-case scenario load.

D.

A combination of 7200 series and 7000 series gateways supports up to 4 nodes

A customer wants to provide wired security as close to the source as possible The wired security must meet the following requirements:

-allow ping from the IT management VLAN to the user VLAN

-deny ping sourcing from the user VLAN to the IT management VLAN

The customer is using Aruba CX 6300s

What is the correct way to implement these requirements?

A.

Apply an outbound ACL on the user VLAN allowing temp echo-reply traffic toward the IT management VLAN

B.

Apply an inbound ACL on the user VLAN allowing icmp echo-reply traffic toward the IT management VLAN

C.

Apply an inbound ACL on the user VLAN denying icmp echo traffic toward the IT management VLAN

D.

Apply an outbound ACL on the user VLAN denying icmp echo traffic toward the IT management VLAN

For the Aruba CX 6400 switch, what does virtual output queueing (VOQ) implement that is different from most typical campus switches?

A.

large ingress packet buffers

B.

large egress packet buffers

C.

per port ASICs

D.

VSX