Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

How can HPE Aruba Networking User-Based Tunneling (UBT) help companies implement a Zero Trust Security strategy?

A.

By extending internal security zones through integration with cloud-based security solutions

B.

By controlling wired and wireless clients with consistent identity- and context-based access policies

C.

By applying best-practice data center security technologies, such as VXLAN, all the way to the internal edge

D.

By applying strong encryption to all traffic that flows through the corporate LAN

A company has a variety of HPE Aruba Networking solutions, including an HPE Aruba Networking infrastructure and HPE Aruba Networking ClearPass Policy Manager (CPPM). The company passes traffic from the corporate LAN destined to the data center through a third-party SRX firewall. The company would like to further protect itself from internal threats. What is one solution that you can recommend?

A.

Have the third-party firewall send Syslogs to CPPM, which can work with network devices to lock internal attackers out of the network.

B.

Add ClearPass Device Insight (CPDI) to the solution, integrate it with the third-party firewall to develop more complete device profiles.

C.

Configure CPPM to poll the third-party firewall for a broad array of information about internal clients, such as profile and posture.

D.

Use tunnel mode SSIDs and user-based tunneling (UBT) on AOS-CX switches to pass all internal traffic directly through the third-party firewall.

A company has AOS-CX switches managed by HPE Aruba Networking Central. The network infrastructure devices authenticate clients to HPE Aruba Networking ClearPass Policy Manager (CPPM), which is integrated with HPE Aruba Networking ClearPass Device Insight (CPDI). You have seen suspicious activity on a client connected to one of the switches. To investigate the client’s activity further, you need to know all of the IP addresses that it has used in the past two weeks.

Where can you find this information collected together?

A.

In CPPM’s Device Profiler dashboard

B.

In HPE Aruba Networking Central’s Audit Trail for the client’s switch

C.

In the logs stored on the client’s switch

D.

In CPDI’s History tab for the client

A company has AOS-CX switches and HPE Aruba Networking ClearPass Policy Manager (CPPM). The company wants switches to implement 802.1X authentication to CPPM and download user roles. What is one task that you must complete on CPPM to support this use case?

A.

Export roles on CPPM to a file that uses XML format.

B.

Create an admin account for the switch on CPPM with the HPE Aruba Networking User Role Download privilege level.

C.

Configure RADIUS enforcement profiles that specify the HPE-User-Role VSA.

D.

Upload the switch TPM certificate as a trusted CA certificate with the Others usage.

A company assigns a different block of VLAN IDs to each of its access layer AOS-CX switches. The switches run version 10.07. The IDs are used for standard

purposes, such as for employees, VolP phones, and cameras. The company wants to apply 802.1X authentication to HPE Aruba Networking ClearPass Policy

Manager (CPPM) and then steer clients to the correct VLANs for local forwarding.

What can you do to simplify setting up this solution?

A.

Assign consistent names to VLANs of the same type across the AOS-CX switches and have user-roles reference names.

B.

Use the trunk allowed VLAN setting to assign multiple VLAN IDs to the same role.

C.

Change the VLAN IDs across the AOS-CX switches so that they are consistent.

D.

Avoid configuring the VLAN in the role; use trunk VLANs to assign multiple VLANs to the port instead.

You are configuring an HPE Aruba Networking VIA solution for a customer. The customer wants this behavior for remote clients that connect to the VPN:

    They forward internet traffic locally.

    They forward traffic destined to the data center over the VPN.

How can you configure this behavior?

A.

Use the firewall role to which users are assigned after VIA Web authentication to configure the forwarding rules.

B.

Use the firewall role to which users are assigned after IKE authentication to configure the forwarding rules.

C.

Enable split tunneling in the VIA Connection Profile and add the data center networks to the tunneled networks list.

D.

Specify the data center networks in a VPN pool; associate that pool to the role to which users are assigned after IKE authentication.

A company requires a centralized audit trail for commands that managers enter on AOS-CX switches.

What can you set up on the switches to meet this requirement?

A.

RADIUS start-stop and interim accounting with the port-access option

B.

Command authorization to HPE Aruba Networking ClearPass Policy Manager (CPPM) acting as a TACACS+ server

C.

SSH public key authentication for all managers who access the AOS-CX switches

D.

Logging to a Syslog server with the severity set at error level

A company wants to use HPE Aruba Networking ClearPass Onboard to issue certificates to BYOD devices. These certificates should be valid only for authenticating the company’s ClearPass cluster.

What type of Onboard CA should you set up?

A.

Intermediate CA with EST disabled

B.

Intermediate CA with EST enabled

C.

Root CA

D.

Registration authority

You have installed an HPE Aruba Networking Network Analytic Engine (NAE) script on an AOS-CX switch to monitor a particular function.

Which additional step must you complete to start the monitoring?

A.

Reboot the switch.

B.

Enable NAE, which is disabled by default.

C.

Edit the script to define monitor parameters.

D.

Create an agent from the script.

You have set up a mirroring session between an AOS-CX switch and a management station, running Wireshark. You want to capture just the traffic sent in the

mirroring session, not the management station ' s other traffic.

What should you do?

A.

Apply this capture filter: ip proto 47

B.

Edit protocol preferences and enable ARUBA_ERM.

C.

Edit protocol preferences and enable HPE_ERM.

D.

Apply this capture filter: udp port 5555