Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

You are setting up an HPE Aruba Networking VIA solution for a company. You need to configure access control policies for applications and resources that remote

clients can access when connected to the VPN.

Where on the VPNC should you configure these policies?

A.

In the tunneled network settings within the VIA Connection Profile

B.

In the cloud security settings using IPsec maps

C.

In the roles to which VIA clients are assigned after IKE authentication

D.

In the roles to which VIA clients are assigned after VIA Web authentication

You are establishing a cluster of HPE Aruba Networking ClearPass servers. (Assume that they are running version 6.9.).

For which type of certificate is it recommended to install a CA-signed certificate on the Subscriber before it joins the cluster?

A.

HTTPS

B.

Database

C.

RADIUS/EAP

D.

RadSec

A company has AOS-CX switches, which authenticate clients to HPE Aruba Networking ClearPass Policy Manager (CPPM). CPPM is set up to receive a variety of information about clients ' profile and posture. New information can mean that CPPM should change a client ' s enforcement profile. What should you set up on the switches to help the solution function correctly?

A.

Enable RADIUS accounting to CPPM, including interim RADIUS accounting.

B.

Configure a RADIUS track that references CPPM ' s FQDN or IP address.

C.

Enable dynamic authorization, and specify CPPM as a dynamic authorization client.

D.

Re-configure the authentication server on the switch specifying CPPM as a TACACS server.

(Note that the HPE Aruba Networking Central interface shown here might look slightly different from what you see in your HPE Aruba Networking Central

interface as versions change; however, similar concepts continue to apply.)

An HPE Aruba Networking 9x00 gateway is part of an HPE Aruba Networking Central group that has the settings shown in the exhibit. What would cause the

gateway to drop traffic as part of its IDPS settings?

A.

Its site-to-site VPN connections failing

B.

Traffic matching a rule in the active ruleset

C.

Its IDPS engine failing

D.

Traffic showing anomalous behavior

A company has AOS-CX switches and is implementing authentication to HPE Aruba Networking ClearPass Policy Manager (CPPM). The company wants to monitor each switch’s connectivity to CPPM. If connectivity is lost, the switch should trigger an alert and collect some information with CLI commands.

What can you do to support this use case?

A.

Enable Control Plane Policing on the switches on the VRF on which they connect to CPPM.

B.

Use the switches’ NAE functions to monitor connectivity to CPPM.

C.

Configure the switches to implement RADIUS accounting to CPPM and enable ClearPass Insight.

D.

Discover the switches within HPE Aruba Networking Central and set up Aruba Central connectivity alerts in the switch group.

You need to create a rule in an HPE Aruba Networking ClearPass Policy Manager (CPPM) role mapping policy that references a ClearPass Device Insight Tag.

Which Type (namespace) should you specify for the rule?

A.

Application

B.

Tips

C.

Device

D.

Endpoint

Refer to the exhibit:

The exhibit shows the TACACS+ enforcement profile that HPE Aruba Networking ClearPass Policy Manager (CPPM) assigns to a manager. When this manager logs into an AOS-CX switch, what does the switch do?

A.

Assigns the manager operator-level privileges

B.

Assigns the manager administrator-level privileges

C.

Rejects the manager with an error message

D.

Assigns the manager auditor-level privileges

You have configured an AOS-CX switch to implement 802.1X on edge ports. Assume ports operate in the default auth-mode. VoIP phones are assigned to the " voice " role and need to send traffic that is tagged for VLAN 12. Where should you configure VLAN 12?

A.

As the trunk native VLAN on edge ports and the trunk native VLAN on the " voice " role.

B.

As the allowed trunk VLAN in the " voice " role (and not in the edge port settings).

C.

As a trunk allowed VLAN on edge ports and the trunk native VLAN in the " voice " role.

D.

As the trunk native VLAN in the " voice " role (and not in the edge port settings).

You need to use " Tips:Posture " conditions within an 802.1X service ' s enforcement policy.

Which guideline should you follow?

A.

Enable caching roles and posture attributes from previous sessions in the service ' s enforcement settings.

B.

Create rules that assign postures in the service ' s role mapping policy.

C.

Enable profiling in the service ' s general settings.

D.

Select the Posture Policy type for the service ' s enforcement policy.

What is a typical use case for using HPE Aruba Networking ClearPass Onboard to provision devices?

A.

Enabling unmanaged devices to succeed at certificate-based 802.1X

B.

Enabling managed Windows domain computers to succeed at certificate-based 802.1X

C.

Enhancing security for loT devices that need to authenticate with MAC-Auth

D.

Enforcing posture-based assessment on managed Windows domain computers