Summer Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exc65

What is an Aruba-recommended best practice for hardening that only applies to Aruba CX 6300 series switches with dedicated management ports?

A.

Implement a control plane ACL to limit access to approved IPs and/or subnets

B.

Manually enable Enhanced Security Mode from a console session.

C.

Disable all management services on the default VRF.

D.

Create a dedicated management VRF, and assign the management port to it.

Your customer currently has Iwo (2) 5406 modular switches with MSTP configured as their core switches. You are proposing a new solution. What would you explain regarding the Aruba CX VSX switch pair when the Primary VSX node is replaced and the system MAC is replaced?

A.

VSX will select the MAC address from a node that is the lower ID.

B.

Configure vMAC on the Primary VSX node under VSX to retain MAC after hardware replacement.

C.

VSX will select the MAC address from a node that is a higher ID.

D.

During the initial VSX configuration, the system-mac is assigned with a fixed MAC based on VSX ID.

A new network design is being considered to minimize client latency in a high-density environment. The design needs to do this by eliminating contention overhead by dedicating subcarriers to clients.

Which technology is the best match for this use case?

A.

OFDMA

B.

MU-MIMO

C.

QWMM

D.

Channel Bonding

A customer just upgraded aggregation layer switches and noticed traffic dropping for 120 seconds after the aggregation layer came online again. What is the best way to avoid having this traffic dropped given the topology below?

A.

Configure the linkup delay timer to 240 seconds to double the amount of lime for the initial phase to sync

B.

Configure the linkup delay timer to exclude LAGS 101 and 102, which will allow time for routing adjacencies to form and to learn upstream routes

C.

Configure the linkup delay timer to include LAGs 101 and 102, which will allow time for routing adjacencies lo form and to learn upstream routes

D.

Configure the linkup delay timer to 120 seconds, which will allow the right amount of time for the initial phase to sync

Refer to the exhibit.

A company has deployed 200 AP-635 access points. To but is not working as expected

What would be the correct action to fix the issue?

A.

Change the SSID to WPA3-Enhanced Open

B.

Change the SSID to WPA3-Enterprise (CCM).

C.

Change the SSID to WPA3-Personal

D.

Change the SSID to WPA3-Enterpnse (CNSA).

A network administrator is troubleshooting some issues guest users are having when connecting and authenticating to the network The access switches are AOS-CX switches.

What command should the administrator use to examine information on which role the guest user has been assigned?

A.

show aaa authentication port-access interface all client-status

B.

show port-access captiveportal profile

C.

show port-access role

D.

diag-dump captiveportal client verbose

Using Aruba best practices what should be enabled for visitor networks where encryption is needed but authentication is not required?

A.

Wi-Fi Protected Access 3 Enterprise

B.

Opportunistic Wireless Encryption

C.

Wired Equivalent Privacy

D.

Open Network Access

A customer is using Aruba Cloud Guest, but visitors keep complaining that the captive portal page keeps coming up after devices go to sleep Which solution should be enabled to deal with this issue?

A.

MAC Caching under the splash page

B.

MAC Caching under the user-role

C.

Wireless Caching under the splash page

D.

MAC Caching under the WLAN

A client is connecting to 802.1X SSID that has been configured in tunnel mode with the default AP-group settings.

After receiving Access-Accept from the RADIUS server, the Aruba Gateway will send Access-Accept to the AP through which tunnel?

A.

IPsec tunnel

B.

Split tunnel

C.

GRE tunnel

D.

PAR tunnel

you are implementing ClearPass Policy Manager with EAP-TLS for authenticating all corporate-owned devices.

What are two possible solutions to the problem of deploying client certificates to corporate MacBooks that are joined to a Windows domain? (Select two.)

A.

ClearPass OnBoard

B.

Windows Server PKl and a GPO

C.

Apple Configurator and a GPO

D.

ClearPass OnGuard

E.

Mobile Device Manager